pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. (CVE-2026-92180)
A local privilege escalation vulnerability exists in the activation-service process of pdfforge PDF Architect. The vulnerability arises from an uncontrolled search path element, allowing a local attacker with low privileges to escalate to SYSTEM level by exploiting the loading of a library from an unsecured location. Exploitation requires prior ability to execute code with limited privileges on the target system.
AI Analysis
Technical Summary
CVE-2026-92180 describes a local privilege escalation vulnerability in the activation-service process of pdfforge PDF Architect. The flaw is due to an uncontrolled search path element where the product loads a library from an insecure location. An attacker who can already execute low-privileged code on the system can exploit this to execute code with SYSTEM privileges. This vulnerability is tracked as ZDI-CAN-29536 and has a CVSS v3.0 score of 7.8, indicating high severity.
Potential Impact
Successful exploitation allows a local attacker to escalate privileges from a low-privileged user to SYSTEM level, potentially leading to full system compromise. Confidentiality, integrity, and availability impacts are all rated high per the CVSS vector.
Mitigation Recommendations
No patch or official fix information is provided in the available data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict local code execution capabilities to trusted users and monitor for suspicious activity related to the activation-service process.
pdfforge PDF Architect activation-service Update Service Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. (CVE-2026-92180)
Description
A local privilege escalation vulnerability exists in the activation-service process of pdfforge PDF Architect. The vulnerability arises from an uncontrolled search path element, allowing a local attacker with low privileges to escalate to SYSTEM level by exploiting the loading of a library from an unsecured location. Exploitation requires prior ability to execute code with limited privileges on the target system.
CVSS v3.0
Score 7.8high
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-92180 describes a local privilege escalation vulnerability in the activation-service process of pdfforge PDF Architect. The flaw is due to an uncontrolled search path element where the product loads a library from an insecure location. An attacker who can already execute low-privileged code on the system can exploit this to execute code with SYSTEM privileges. This vulnerability is tracked as ZDI-CAN-29536 and has a CVSS v3.0 score of 7.8, indicating high severity.
Potential Impact
Successful exploitation allows a local attacker to escalate privileges from a low-privileged user to SYSTEM level, potentially leading to full system compromise. Confidentiality, integrity, and availability impacts are all rated high per the CVSS vector.
Mitigation Recommendations
No patch or official fix information is provided in the available data. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict local code execution capabilities to trusted users and monitor for suspicious activity related to the activation-service process.
Technical Details
- Gcve Source
- db.gcve.eu
- Osv Id
- GHSA-5whf-f6fj-76rg
- Osv Schema Version
- 1.4.0
- Aliases
- ["CVE-2026-92180"]
- Database Specific Severity
- HIGH
- Cvss Version
- 3.0
- State
- PUBLISHED
Threat ID: 6aaa07e855bf5e2cf5ea3458
Added to database: 09/16/2026, 03:07:20 UTC
Last enriched: 09/16/2026, 03:46:30 UTC
Last updated: 09/16/2026, 04:41:33 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.