CVE-2026-81996: Acrobat Reader | Incorrect Authorization (CWE-863)
Published Sep 8, 2026
·Updated
Acrobat Reader is affected by an Incorrect Authorization vulnerability that could result in privilege escalation. A low-privileged attacker could exploit this vulnerability to gain elevated access. Exploitation of this issue does not require user interaction. Scope is changed.
Affected Software
1 affected component
Adobe Acrobat Reader
Event History
Sep 8, 2026
CVE Published
via MITRE·08:30 PM
Data Sourced
via MITRE·08:30 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What level of access does an attacker need before exploiting this issue?
The attacker must already have low-privileged access to the affected system. Exploitation does not require user interaction.
2
What is the potential impact after successful exploitation?
A successful exploit could allow a low-privileged attacker to gain elevated access. The reported impact includes high confidentiality, integrity, and availability effects, with changed scope.