rootpwn

high · CVSS v3 7.1

CVE-2026-91789

Adobe Acrobat Reader and related PDF processing components are vulnerable to an out-of-bounds read/write when parsing malformed U3D, PRC, Ac

Overview

Adobe Acrobat Reader and related PDF processing components are vulnerable to an out-of-bounds read/write when parsing malformed U3D, PRC, AcroForms, JPEG/JPEG2000, or annotation streams. The flaw can cause crashes or remote code execution, potentially exposing sensitive data or allowing attackers to compromise systems. It is critical for organizations that rely on PDF handling to apply patches promptly.

Description

Addressed potential issues where the application could be exposed to an Out-of-Bounds Read/Write vulnerability and crash when handling certain U3D files, PRC files, AcroForms, JPEG/JPEG2000 images, or annotations with malformed streams or data, which attackers could exploit to execute remote code or disclose information. This occurs due to a lack of proper validation of user-supplied data before performing operations on objects.

Impact

Confidentiality: potential data disclosure via malformed streams. Integrity: possible tampering or unauthorized code execution. Availability: application crashes leading to denial of service. Defenders: end-users, IT admins, security teams managing PDF workflows.

Remediation

Apply the latest Adobe security update for CVE-2026-91789. If patch not available, disable U3D/PRC/AcroForms support or block malformed PDFs via content filtering. Use application whitelisting and monitor for abnormal PDF parsing errors.

Risk context

High severity (CVSS 7.1) indicates significant risk; organizations should treat this as a priority vulnerability, especially those processing PDFs from untrusted sources.

Affected products

  • Adobe Acrobat Reader
  • Adobe Acrobat DC
  • Adobe Reader DC
  • Adobe Acrobat Pro
  • Adobe Acrobat XI
  • Adobe Reader XI
  • Adobe Reader 2023
  • Adobe Acrobat 2023

Scores

Severity
high
CVSS v2
5.8
CVSS v3
7.1
CVSS v4
EPSS

Adobe PDF Out-of-Bounds Remote Code Execution Denial of Service Data Disclosure Patch Security Update

← All CVEs