CVE-2026-2040
PDF-XChange Editor vulnerability analysis and mitigation

Overview

CVE-2026-2040 is a local privilege escalation vulnerability in PDF-XChange Editor caused by an uncontrolled search path element (CWE-427) in the TrackerUpdate process. It affects PDF-XChange Editor versions prior to 10.7.3.401. The vulnerability was reported to the vendor on September 16, 2025, and publicly disclosed on February 19, 2026, via a coordinated release. It carries a CVSS v3.0 base score of 7.3 (High) (ZDI Advisory).

Technical details

The root cause is an uncontrolled search path element (CWE-427) within the TrackerUpdate process of PDF-XChange Editor, which loads a library from an unsecured or attacker-controllable location. This is a classic DLL search order hijacking scenario (MITRE ATT&CK T1574.001), where an attacker with low-privileged code execution can place a malicious library in a directory that the TrackerUpdate process searches before the legitimate library path. Exploitation requires the attacker to already have low-privileged local code execution and requires user interaction to trigger the vulnerable library load. The vulnerability was discovered by Kolja Grassmann of Neodyme AG and reported through the Zero Day Initiative program (ZDI Advisory).

Impact

Successful exploitation allows a local attacker to escalate privileges and execute arbitrary code in the context of a target user, resulting in high impact to confidentiality, integrity, and availability. An attacker who compromises a low-privileged account could leverage this vulnerability to gain elevated access, potentially enabling access to sensitive data, modification of system files, or further lateral movement within the environment. The scope is unchanged, meaning the impact is contained to the affected system rather than crossing privilege boundaries to other components (ZDI Advisory).

Exploitability

The Zero Day Initiative published an advisory for this vulnerability on February 19, 2026, which serves as a public reference that could aid in exploit development. No public proof-of-concept exploit code or evidence of in-the-wild exploitation has been reported at this time. The EPSS score is approximately 0.014% (0.000140), indicating a low probability of exploitation in the near term. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. Qualys has added detection for this vulnerability (detection ID 386668) (ZDI Advisory).

Exploitation steps

  1. Gain low-privileged access: Obtain the ability to execute code on the target system as a low-privileged user (e.g., via phishing, exploitation of another vulnerability, or legitimate user account access).
  2. Identify the vulnerable path: Locate the unsecured directory from which the PDF-XChange Editor TrackerUpdate process loads its library. This can be done by monitoring process activity with tools like Process Monitor (Procmon) to observe DLL load attempts and identify directories searched before the legitimate library location.
  3. Craft a malicious DLL: Create a malicious dynamic-link library (DLL) with the same name as the library the TrackerUpdate process attempts to load, containing attacker-controlled code (e.g., a reverse shell or privilege escalation payload).
  4. Place the malicious DLL: Copy the crafted DLL into the unsecured directory identified in step 2, which the low-privileged attacker has write access to.
  5. Trigger the vulnerable load: Induce user interaction or wait for the TrackerUpdate process to execute (e.g., by launching PDF-XChange Editor or triggering an update check), causing it to load the malicious DLL instead of the legitimate one.
  6. Achieve privilege escalation: The malicious DLL executes in the context of the target user with elevated privileges, granting the attacker code execution at a higher privilege level (ZDI Advisory).

Indicators of compromise

  • File System: Unexpected or newly created DLL files in directories writable by low-privileged users that are part of the PDF-XChange Editor or TrackerUpdate process search path; DLL files with names matching legitimate PDF-XChange libraries but located outside the standard installation directory (e.g., C:\Program Files\Tracker Software\PDF Editor\).
  • Process: Unusual child processes spawned by the TrackerUpdate process (e.g., cmd.exe, powershell.exe, network tools); TrackerUpdate loading DLLs from non-standard or user-writable directories as observed in process monitoring tools.
  • Logs: Windows Event Logs showing unexpected process creation events originating from the TrackerUpdate process; application event log entries indicating DLL load failures followed by loads from alternate paths.

Mitigation and workarounds

PDF-XChange has released a fix in version 10.7.3.401, which resolves the insecure library loading behavior in the TrackerUpdate process. Users should update PDF-XChange Editor to version 10.7.3.401 or later as the primary remediation. As a temporary workaround, administrators can restrict write permissions on directories in the TrackerUpdate process's DLL search path to prevent low-privileged users from placing malicious libraries. Applying the principle of least privilege and monitoring for unexpected DLL loads via endpoint detection tools can also reduce risk (ZDI Advisory).

Additional resources


SourceThis report was generated using AI

Related PDF-XChange Editor vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-64086HIGH7.5
  • PDF-XChange Editor logoPDF-XChange Editor
  • cpe:2.3:a:pdf-xchange:pdf-xchange_editor
NoNoDec 09, 2025
CVE-2025-64085HIGH7.5
  • PDF-XChange Editor logoPDF-XChange Editor
  • cpe:2.3:a:pdf-xchange:pdf-xchange_editor
NoNoDec 09, 2025
CVE-2026-2040HIGH7.3
  • PDF-XChange Editor logoPDF-XChange Editor
  • cpe:2.3:a:pdf-xchange:pdf-xchange_editor
NoNoFeb 20, 2026
CVE-2025-58113MEDIUM6.5
  • PDF-XChange Editor logoPDF-XChange Editor
  • cpe:2.3:a:pdf-xchange:pdf-xchange_editor
NoNoDec 02, 2025
CVE-2025-47152MEDIUM6.5
  • PDF-XChange Editor logoPDF-XChange Editor
  • cpe:2.3:a:pdf-xchange:pdf-xchange_editor
NoNoAug 05, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management