CVE-2026-92180
Received Received - Intake

Uncontrolled Search Path Element in PDF Architect

Vulnerability report for CVE-2026-92180, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-16

Assigner: Zero Day Initiative

Description

pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of pdfforge PDF Architect. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the activation-service process. The product loads a library from an unsecured location. An attacker can leverage this vulnerability to escalate privileges and execute code in the context of SYSTEM. Was ZDI-CAN-29536.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-16
Generated
2026-10-06
AI Q&A
2026-09-16
EPSS Evaluated
2026-10-04
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
pdfforge pdf_architect *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-427 The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a local privilege escalation flaw in pdfforge PDF Architect. It exists in the activation-service process which loads a library from an unsecured location. An attacker with low-privileged code execution can exploit this to gain SYSTEM-level privileges.

Detection Guidance

Detection of this vulnerability requires checking for the presence of the pdfforge PDF Architect activation-service process and verifying if it loads libraries from unsecured locations. Monitor for unusual privilege escalation attempts or SYSTEM-level processes spawned by low-privileged users. Use process monitoring tools like Process Explorer or Windows Event Viewer to inspect the activation-service process and its loaded modules.

Impact Analysis

If exploited, this vulnerability allows attackers to elevate their privileges from low-level access to SYSTEM-level access on affected systems. This could enable them to install programs, view or delete data, or create new accounts with full privileges.

Compliance Impact

This vulnerability allows local attackers to escalate privileges to SYSTEM-level access, which could lead to unauthorized access to sensitive data. This may violate compliance requirements under GDPR and HIPAA that mandate strict access controls and protection of personal or health information.

Mitigation Strategies

Restrict interaction with the pdfforge PDF Architect product to prevent exploitation. This includes limiting access to the activation-service process and ensuring untrusted users cannot execute code on the system.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-92180. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart