๐Ÿ” CVE Alert

CVE-2026-107735

UNKNOWN 0.0

SumatraPDF: `sumatrapdfrestrict.ini` never revokes any permission (fail-open policy initialization)

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

SumatraPDF is a multi-format reader for Windows. In 3.6.1 and earlier, InitializePolicies() starts the sumatrapdfrestrict.ini path with gPolicyRestrictions set to Perm::All and only ORs permission bits, so the INI file never revokes permissions. Deploying SumatraPDF with this INI file, including a malformed file or zero-valued permission settings, can silently bypass configured disk, network, printing, registry, clipboard, preference, and fullscreen restrictions. The -restrict command-line path works correctly and is not affected. No fixed version is available as of this review.

CWE CWE-636
Vendor sumatrapdfreader
Product sumatrapdf
Published Oct 8, 2026
Stay Ahead of the Next One

Get instant alerts for sumatrapdfreader sumatrapdf

Be the first to know when new unknown vulnerabilities affecting sumatrapdfreader sumatrapdf are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

sumatrapdfreader / sumatrapdf
<= 3.6.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/sumatrapdfreader/sumatrapdf/security/advisories/GHSA-crhm-w5qr-wjj4 github.com: https://github.com/sumatrapdfreader/sumatrapdf/commit/f72948b59405d3ddba527789898050ef411d0bb8