🛡️ CVE-2026-3780
🟠 CVSS 7.3 — High ✅ No Known Exploit CWE-426 NVD
7.3
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

The application's installer runs with elevated privileges but resolves system executables and DLLs using untrusted search paths that can include user-writable directories, allowing a local attacker to place malicious binaries with the same names and have them loaded or executed instead of the legitimate system files, resulting in local privilege escalation.

Details

Severity HIGH
CVSS Score 7.3
CVSS Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CWE CWE-426
Public Exploit ✅ No
Source NVD
Published 2026-04-01
Updated 2026-06-02
Modified 2026-04-28
Fix URL N/A

Affected Packages

Software From version Fixed in
pdf-editor 2025.1.0.27937 2025.3.0.35737
pdf-reader 2025.3.0.35737

Similar Threats

Free Vulnerability Check

Is your WordPress site affected?

BotEraser helps you identify potentially vulnerable plugins and themes by checking your installation against known CVE records.

Scan My Site Free →

No credit card required  ·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.