Description
A flaw has been found in Artifex MuPDF up to 1.26.1 on Windows. The impacted element is the function get_system_dpi of the file platform/x11/win_main.c. This manipulation causes uncontrolled search path. The attack requires local access. The attack is considered to have high complexity. The exploitability is regarded as difficult. Upgrading to version 1.26.2 is sufficient to resolve this issue. Patch name: ebb125334eb007d64e579204af3c264aadf2e244. Upgrading the affected component is recommended.
References (6)
Core 6
Core References
Permissions Required, VDB Entry vdb-entry
technical-description
https://vuldb.com/?id.344924
Permissions Required, VDB Entry signature
permissions-required
https://vuldb.com/?ctiid.344924
Permissions Required, VDB Entry third-party-advisory
https://vuldb.com/?submit.750978
Patch patch
https://cgit.ghostscript.com/cgi-bin/cgit.cgi/mupdf.git/commit/?id=ebb125334eb007d64e579204af3c264aadf2e244
Various Sources patch
https://casper.mupdf.com/downloads/archive/mupdf-1.26.2-windows.zip
Various Sources product
https://artifex.com/
Scores
CVSS v3
7.0
EPSS
0.0011
EPSS Percentile
1.9%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-426
CWE-427
Status
published
Products (3)
Artifex/MuPDF
1.26.0
Artifex/MuPDF
1.26.1
Artifex/MuPDF
1.26.2
Published
Feb 10, 2026
Tracked Since
Feb 18, 2026