CVE-2026-107735
Deferred Deferred - Pending Action

SumatraPDF Policy Bypass via malformed sumatrapdfrestrict.ini

Vulnerability report for CVE-2026-107735, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-08

Last updated on: 2026-10-08

Assigner: GitHub, Inc.

Description

SumatraPDF is a multi-format reader for Windows. In 3.6.1 and earlier, InitializePolicies() starts the sumatrapdfrestrict.ini path with gPolicyRestrictions set to Perm::All and only ORs permission bits, so the INI file never revokes permissions. Deploying SumatraPDF with this INI file, including a malformed file or zero-valued permission settings, can silently bypass configured disk, network, printing, registry, clipboard, preference, and fullscreen restrictions. The -restrict command-line path works correctly and is not affected. No fixed version is available as of this review.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-08
Last Modified
2026-10-08
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
sumatrapdfreader sumatrapdf <= 3.6.1

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-636 When the product encounters an error condition or failure, its design requires it to fall back to a state that is less secure than other options that are available, such as selecting the weakest encryption algorithm or using the most permissive access control restrictions.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

SumatraPDF versions 3.6.1 and earlier have a flaw in InitializePolicies() where permission restrictions set in sumatrapdfrestrict.ini are not properly enforced. The function starts with all permissions allowed and only adds permissions, meaning malformed or zero-valued settings in the INI file cannot revoke access. This allows bypassing disk, network, printing, registry, clipboard, preference, and fullscreen restrictions silently.

Detection Guidance

Check for the presence of sumatrapdfrestrict.ini files in SumatraPDF installation directories or user profiles. Inspect the file for malformed content or zero-valued permission settings. Verify if the -restrict command-line path is used, as it is not affected by this issue.

Impact Analysis

If you use SumatraPDF with a sumatrapdfrestrict.ini file, an attacker could bypass configured security restrictions, potentially accessing restricted files, network resources, or system settings without detection. The -restrict command-line path is unaffected and works correctly.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating compliance requirements under GDPR, HIPAA, or other regulations that mandate strict access controls and auditability. Unauthorized data exposure or modification risks non-compliance penalties.

Mitigation Strategies

Avoid using sumatrapdfrestrict.ini files for permission restrictions. Use the -restrict command-line path instead. Ensure no malformed or zero-valued permission settings exist in any deployed INI files. Consider alternative PDF readers until a fixed version is available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-107735. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart