HIGH

CVE-2026-34621

Adobe Acrobat Dc 2026-04-11 CVSS v3.1
CVSS
8.6
KEV

Description

Acrobat Reader versions 24.001.30356, 26.001.21367 and earlier are affected by an Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Summary dbcve.org

Adobe Acrobat Reader contains a Prototype Pollution vulnerability where improperly controlled modification of object prototype attributes could allow arbitrary code execution in the current user's context. This occurs when the application processes malicious files that manipulate JavaScript object prototypes.

Mitigation

Update Adobe Acrobat Reader to version 26.001.21368 or later for the 26.x branch, or 24.001.30357 or later for the 24.x branch. Additionally, educate users to avoid opening untrusted PDF files from unknown sources.

Weakness (CWE)

CWE-1321

EPSS Score

7.09%
Probability of exploitation in next 30 days
93.9th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE