CVE-2026-47937: Acrobat Reader | Uncontrolled Search Path Element (CWE-427)
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an Uncontrolled Search Path Element vulnerability that could result in arbitrary code execution in the context of the current user. An attacker with high privileges could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-47937?
CVE-2026-47937 has a severity rating of high, with a score of 7.4.
What software is affected by CVE-2026-47937?
CVE-2026-47937 affects Adobe Acrobat Reader versions 24.001.30365, 26.001.21651, and earlier.
How does CVE-2026-47937 affect users?
CVE-2026-47937 can lead to arbitrary code execution in the context of the current user and requires user interaction.
How do I mitigate CVE-2026-47937?
To mitigate CVE-2026-47937, users should update Adobe Acrobat Reader to the latest version released after the vulnerabilities.
What is the primary risk associated with CVE-2026-47937?
The primary risk associated with CVE-2026-47937 is the potential for an attacker to execute arbitrary code on a victim's machine.