
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-81997 is an Incorrect Authorization vulnerability (CWE-863) in Adobe Acrobat and Acrobat Reader that allows a local attacker to bypass security features and gain unauthorized write access. Disclosed on September 8, 2026, it affects Adobe Acrobat and Acrobat Reader (Continuous track) versions 26.002.21900 and earlier, and Acrobat 2024 versions 24.001.30383 and earlier, on both Windows and macOS. Exploitation requires a victim to open a malicious PDF file. The vulnerability carries a CVSS v3.1 base score of 6.3 (Medium) (Adobe Advisory, GitHub Advisory).
The vulnerability is classified as CWE-863 (Incorrect Authorization), meaning the application fails to correctly perform authorization checks when an actor attempts to access a resource or perform an action. The attack vector is local, requiring low complexity and no privileges, but does require user interaction — specifically, a victim must open a crafted malicious PDF file. When exploited, the scope changes beyond the vulnerable component, enabling unauthorized write access to resources outside the normal security boundary of Acrobat Reader (Adobe Advisory, GitHub Advisory).
Successful exploitation allows an attacker to bypass security measures enforced by Adobe Acrobat Reader and gain unauthorized write access to files or system resources, with a high integrity impact and a changed scope. Confidentiality and availability are not directly impacted by this vulnerability. The scope change indicates that the impact can extend beyond the Acrobat Reader process itself to affect other components or files on the system (Adobe Advisory, GitHub Advisory).
As of the disclosure date, there is no public proof-of-concept exploit and no evidence of active in-the-wild exploitation (Adobe Advisory). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.152% (0.00162), placing it in the 5th percentile for exploitation likelihood within 30 days. Exploitation is not automatable and requires user interaction, reducing the overall risk of widespread exploitation (GitHub Advisory).
Adobe has released patched versions addressing this vulnerability: Acrobat and Acrobat Reader (Continuous) version 26.002.21901 or later, and Acrobat 2024 version 24.001.30429 or later. Users should update to the latest available version via Adobe's update mechanism or by downloading directly from Adobe. As a precautionary measure, users should avoid opening PDF files from untrusted or unknown sources, and organizations may consider implementing application whitelisting or restricting PDF macro/JavaScript execution where policy permits (Adobe Advisory).
The vulnerability was noted in the context of Adobe's September 2026 patch release, which addressed multiple products. The CIS Security advisory flagged the broader Adobe September 2026 update as addressing vulnerabilities that could allow for arbitrary code execution across multiple Adobe products. No significant independent researcher commentary or notable social media discussion specific to CVE-2026-81997 has been identified beyond standard vulnerability tracking and aggregation sites.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."