
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-2040 is a local privilege escalation vulnerability in PDF-XChange Editor caused by an uncontrolled search path element (CWE-427) in the TrackerUpdate process. It affects PDF-XChange Editor versions prior to 10.7.3.401. The vulnerability was reported to the vendor on September 16, 2025, and publicly disclosed on February 19, 2026, via a coordinated release. It carries a CVSS v3.0 base score of 7.3 (High) (ZDI Advisory).
The root cause is an uncontrolled search path element (CWE-427) within the TrackerUpdate process of PDF-XChange Editor, which loads a library from an unsecured or attacker-controllable location. This is a classic DLL search order hijacking scenario (MITRE ATT&CK T1574.001), where an attacker with low-privileged code execution can place a malicious library in a directory that the TrackerUpdate process searches before the legitimate library path. Exploitation requires the attacker to already have low-privileged local code execution and requires user interaction to trigger the vulnerable library load. The vulnerability was discovered by Kolja Grassmann of Neodyme AG and reported through the Zero Day Initiative program (ZDI Advisory).
Successful exploitation allows a local attacker to escalate privileges and execute arbitrary code in the context of a target user, resulting in high impact to confidentiality, integrity, and availability. An attacker who compromises a low-privileged account could leverage this vulnerability to gain elevated access, potentially enabling access to sensitive data, modification of system files, or further lateral movement within the environment. The scope is unchanged, meaning the impact is contained to the affected system rather than crossing privilege boundaries to other components (ZDI Advisory).
The Zero Day Initiative published an advisory for this vulnerability on February 19, 2026, which serves as a public reference that could aid in exploit development. No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported at this time. The EPSS score is approximately 0.014% (0.000140), indicating a low probability of exploitation in the near term. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Qualys has added detection for this vulnerability (detection ID 386668) (ZDI Advisory).
C:\Program Files\Tracker Software\PDF Editor\).cmd.exe, powershell.exe, network tools); TrackerUpdate loading DLLs from non-standard or user-writable directories as observed in process monitoring tools.PDF-XChange has released a fix in version 10.7.3.401, which resolves the insecure library loading behavior in the TrackerUpdate process. Users should update PDF-XChange Editor to version 10.7.3.401 or later as the primary remediation. As a temporary workaround, administrators can restrict write permissions on directories in the TrackerUpdate process's DLL search path to prevent low-privileged users from placing malicious libraries. Applying the principle of least privilege and monitoring for unexpected DLL loads via endpoint detection tools can also reduce risk (ZDI Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."