CVE-2026-46529PoC

MEDIUMCVSS 8.4 · HIGH

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Patch affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote code execution vulnerability in versions prior to 1.26.3 and 1.28.4 allows an attacker to achieve arbitrary code execution as the user by tricking them into clicking a link inside a malicious PDF document. The PDF can be packaged as a polyglot file that is simultaneously a valid PDF and a valid ELF shared library, making the attack a single-file, single-click, configuration-independent RCE on stock atril installations. The root cause is `shell/ev-application.c:ev_spawn`, which builds a command line from attacker-controlled PDF link-destination fields without applying `g_shell_quote`. The cmdline is then handed to `g_app_info_create_from_commandline`, which shell-parses it back into argv — splitting any embedded `--gtk-module=PATH` into a separate argv element. GTK then `dlopen()`s the path during init, running any `__attribute__((constructor))` it finds. Versions 1.26.3 and 1.28.4 contain a patch for the issue. This is the same defect class as CVE-2023-51698 (CBT `--checkpoint-action` injection in `comics-document.c`, fixed in 1.6.2) but in a different code path (`shell/ev-application.c`) that the original patch did not touch.

4.3/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-77CWE-88CWE-829

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 17 mentions across 12 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 8 signals
  • PoC mentioned or linked in 11 signals
  • Patch or workaround mentioned in 5 signals
  • Technical details provided in 14 signals
  • Disclosure: 3 classified signals
  • Peaked 9d ago at 4 mentions (2026-05-22); latest day: 1
  • 17 total mentions across 12 days

Deep dive

Activity timeline17 mentions / 12d
01234Mentions · 2026-05-20: 1Mentions · 2026-05-21: 1Mentions · 2026-05-22: 4Mentions · 2026-05-23: 3Mentions · 2026-05-28: 1Mentions · 2026-05-29: 1Mentions · 2026-06-04: 1Mentions · 2026-06-05: 1Mentions · 2026-06-14: 1Mentions · 2026-06-27: 1Mentions · 2026-06-28: 1Mentions · 2026-08-27: 1PoC Mentioned / Linked · 2026-05-21: 1PoC Mentioned / Linked · 2026-05-22: 3PoC Mentioned / Linked · 2026-05-23: 1PoC Mentioned / Linked · 2026-05-28: 1PoC Mentioned / Linked · 2026-05-29: 1PoC Mentioned / Linked · 2026-06-05: 1PoC Mentioned / Linked · 2026-06-14: 1PoC Mentioned / Linked · 2026-06-28: 1PoC Mentioned / Linked · 2026-08-27: 1Exploit Tool / Code · 2026-05-22: 2Exploit Tool / Code · 2026-05-23: 1Exploit Tool / Code · 2026-05-28: 1Exploit Tool / Code · 2026-05-29: 1Exploit Tool / Code · 2026-06-05: 1Exploit Tool / Code · 2026-06-28: 1Exploit Tool / Code · 2026-08-27: 1Patch / Workaround · 2026-05-20: 1Patch / Workaround · 2026-05-22: 3Patch / Workaround · 2026-05-23: 1Technical Details · 2026-05-20: 1Technical Details · 2026-05-21: 1Technical Details · 2026-05-22: 3Technical Details · 2026-05-23: 2Technical Details · 2026-05-28: 1Technical Details · 2026-05-29: 1Technical Details · 2026-06-05: 1Technical Details · 2026-06-14: 1Technical Details · 2026-06-27: 1Technical Details · 2026-06-28: 1Technical Details · 2026-08-27: 105-2005-2105-2205-2305-2805-2906-0406-0506-1406-2706-2808-27
Signal classification5 categories
PoC
635.3%
Disclosure
317.6%
Exploit
317.6%
General
317.6%
Patch
211.8%
Referenced assets11 URLs
Classification over time
DateTotalLabels
2026-05-201
Patch1
2026-05-211
PoC1
2026-05-224
Disclosure1Patch1PoC2
2026-05-233
Exploit1General2
2026-05-281
PoC1
2026-05-291
Exploit1
2026-06-041
General1
2026-06-051
PoC1
2026-06-141
Disclosure1
2026-06-271
Disclosure1
2026-06-281
Exploit1
2026-08-271
PoC1
Full discourse17 posts
  • Densel@luckyhacker43
    Disclosure

    10-Year-Old RCE Found in Linux PDF Viewers 🤯🔥 CVE-2026-46529 affects XReader, Evince, and Atril, allowing code execution through a malicious PDF. Huge find by N1et 👏 🔗 https://medeiros.zip/posts/CVE-2026-46529-evince #CyberSecurity #Linux #RCE #CVE Join team 👉https://t.me/luckyhacker43 https://t.co/yMmze9CqPf

    Post summary

    A newly disclosed 10‑year‑old RCE vulnerability (CVE-2026-46529) affects Linux PDF viewers XReader, Evince, and Atril, allowing code execution via a malicious PDF. The post includes a link that presumably contains further details and potential PoC.

    03912081009.0K
    2.9K followersView on X
  • Medeirus@jmedeiros1337
    PoC

    Publiquei minha pesquisa sobre uma vulnerabilidade de RCE em visualizadores PDF Linux como Atril, Evince e Xreader, resultando na CVE-2026-46529. Abrindo o PDF, e clicando qualquer parte da pagina um comando arbitrário é executado no sistema O artigo: https://medeiros.zip/posts/CVE-2026-46529-evince https://t.co/XOPILc4d8C

    Post summary

    The author publishes research on a new RCE in Linux PDF viewers (CVE‑2026‑46529) and provides links that presumably contain proof‑of‑concept details. No mention of active exploitation, patch, or false positive status.

    621085508.4K
    64 followersView on X
  • Juliano Rizzo@julianor
    General

    1/ From all the recent writeups, I pick a few to read carefully and enjoy while drinking 🧉 and eating chipa, the way I did before with every (yes) Bugtraq post. This week: Qualys ptrace LPE, CVE-2026-46333 — no AI Linux PDF RCE, CVE-2026-46529 — human+AI Both are worth reading:

    Post summary

    The tweet mentions two CVEs with minimal technical descriptors but provides no evidence of PoC, exploit code, active exploitation, patch, or false positive claims.

    18062296.1K
    9.5K followersView on X
  • yousukezan@yousukezan
    PoC

    Linux向けPDFビューア「Evince」「Atril」「xreader」に、細工されたPDFファイルを開くだけで任意コード実行につながる深刻な脆弱性「CVE-2026-46529」が報告された。 公開された検証コードによると、PDF内部の/GoToRアクションと引数処理の不備を悪用し、外部ライブラリを読み込ませることで、利用者権限で任意コードを実行できるという。 影響を受けるのは、Atril 1.28.4未満、xreader 4.6.3未満、GTK3版Evince 48.1未満など。研究者の João Medeiros 氏はGitHub上でPoCを公開しており、PDFとELF共有ライブラリを一体化した「ポリグロットファイル」を用いることで、閲覧時のクリック操作だけでリバースシェルを起動できるとしている。 脆弱性は長年存在していた可能性があり、原因はユーザー制御可能な文字列を適切にエスケープせずコマンドラインへ渡していた点にある。GTK4版Evinceでは特定の悪用経路が無効化されているものの、根本的な引数注入自体は残ると指摘されている。利用者には速やかなアップデート適用が推奨される。 https://github.com/N1et/CVE-2026-46529

    Post summary

    CVE‑2026‑46529 is a critical vulnerability in Evince, Atril, and xreader allowing arbitrary code execution via crafted PDFs; a PoC has been published on GitHub, and users are urged to apply updates promptly.

    017137104.0K
    14.5K followersView on X
  • I'M H4CK3R 42@luckyhacker43
    PoC

    CVE-2026-46529: 10-year-old RCE in Linux PDF Viewer (XReader/Evince/Atril) by N1et 🤯🔥 👨‍💻 João Medeiros (N1et) 🔗 https://medeiros.zip/posts/CVE-2026-46529-evince 🔗 https://github.com/mate-desktop/atril/security/advisories/GHSA-vgv2-m826-8f6f 🔗 https://github.com/N1et/CVE-2026-46529 🔗https://t.me/luckyhacker42 https://t.co/4RjUxGbXsk

    Post summary

    A 10‑year‑old remote code execution vulnerability (CVE-2026-46529) in Linux PDF viewers XReader, Evince, and Atril has been disclosed, with a PoC available on GitHub. No evidence of live exploitation or patch updates is mentioned.

    02035162.1K
    5.0K followersView on X
  • Komodo Cyber Security@Komodosec
    Disclosure

    CVE-2026-46529: 10-year-old RCE in Linux PDF Viewer (XReader/Evince/Atril) https://medeiros.zip/posts/CVE-2026-46529-evince?utm_source=dlvr.it&utm_medium=twitter

    Post summary

    The linked article announces a 10‑year‑old remote code execution flaw in Linux PDF viewers XReader, Evince, and Atril, but provides no evidence of active exploitation, patch, or PoC.

    01202781.9K
    1.5K followersView on X
  • Densel@luckyhacker43
    PoC

    CVE-2026-46529: 10-year-old RCE in Linux PDF Viewer (XReader/Evince/Atril) by N1et 🤯🔥 👨‍💻 João Medeiros (N1et) 🔗 https://medeiros.zip/posts/CVE-2026-46529-evince 🔗 https://github.com/mate-desktop/atril/security/advisories/GHSA-vgv2-m826-8f6f 🔗 https://github.com/N1et/CVE-2026-46529 More resources on my bio. https://t.co/GOchoE68AF

    Post summary

    The tweet announces a 10‑year‑old remote code execution vulnerability in Linux PDF viewers, sharing links to a proof‑of‑concept repository and a security advisory, but does not mention active exploitation, patches, or a false‑positive claim.

    0701891.2K
    2.5K followersView on X
  • yousukezan@yousukezan
    Disclosure

    Linux向けPDFビューア「Evince」「Atril」「xreader」に、細工されたPDFファイルを開くだけで任意コード実行につながる深刻な脆弱性「CVE-2026-46529」が報告された。 公開された検証コードによると、PDF内部の/GoToRアクションと引数処理の不備を悪用し、外部ライブラリを読み込ませることで、利用者権限で任意コードを実行できるという。 影響を受けるのは、Atril 1.28.4未満、xreader 4.6.3未満、GTK3版Evince 48.1未満など。研究者の João Medeiros 氏はGitHub上でPoCを公開しており、PDFとELF共有ライブラリを一体化した「ポリグロットファイル」を用いることで、閲覧時のクリック操作だけでリバースシェルを起動できるとしている。 脆弱性は長年存在していた可能性があり、原因はユーザー制御可能な文字列を適切にエスケープせずコマンドラインへ渡していた点にある。GTK4版Evinceでは特定の悪用経路が無効化されているものの、根本的な引数注入自体は残ると指摘されている。利用者には速やかなアップデート適用が推奨される。 https://github.com/N1et/CVE-2026-46529

    Post summary

    The article reports a severe CVE‑2026‑46529 affecting Evince, Atril, and xreader, provides technical details and a PoC, and urges users to apply available updates.

    020811.3K
    14.5K followersView on X
  • Open Source Security mailing list@oss_security
    Patch

    CVE-2026-46529: Evince/Atril/Xreader: Command injection https://www.openwall.com/lists/oss-security/2026/05/19/34 caused by missing quoting of shell-like input in ev_spawn() in ev-application.c. It is fixed by: • Evince 48.2 • Atril 1.28.4 and 1.26.3 • Xreader 4.6.4 and 3.6.7 details private until May 21

    Post summary

    CVE-2026-46529 is a command injection vulnerability in Evince, Atril, and Xreader; the issue and its mitigations are clearly outlined, with no evidence of active exploitation or a PoC.

    110701.0K
    4.7K followersView on X
  • kokumօtօ@__kokumoto
    PoC

    Kali Linux等で使用されている文書表示ソフトAtril Document Viewerに遠隔コード実行の脆弱性。CVE-2026-46529はアクセスPDF内のリンクをクリックさせることで発動可能。g_shell_quoteサニタイズ関数の適用不備。PoC(攻撃の概念実証コード)公開済み。 https://securityonline.info/atril-single-click-rce-cve-2026-46529/

    Post summary

    A proof‑of‑concept for CVE‑2026‑46529 in Atril Document Viewer has been released, showing that clicking a PDF link can trigger remote code execution via a g_shell_quote sanitization flaw.

    01031875
    7.6K followersView on X
  • Daily CyberSecurity@the_yellow_fall
    Exploit

    Learn about the critical Atril single-click RCE vulnerability (CVE-2026-46529). Public details and exploit code are now fully disclosed. #Cybersecurity #Linux #RCE #Infosec #Vulnerability #Atril https://securityonline.info/atril-single-click-rce-cve-2026-46529/ https://t.co/L3N8CDYA25

    Post summary

    The post announces that CVE-2026‑46529, a single-click RCE in Atril, is fully disclosed with exploit code available, with no active exploitation or patch information provided.

    01011801
    12.4K followersView on X
  • Open Source Security mailing list@oss_security
    PoC

    CVE-2026-46529: Evince/Atril/Xreader: Command injection - full reports available now https://www.openwall.com/lists/oss-security/2026/05/21/7 script for building malicious polyglot PDFs that are simultaneously both valid PDF files and also valid ELF binaries. Click on a link to load this as a GTK module.

    Post summary

    A command injection vulnerability (CVE‑2026‑46529) is announced, with a link to full reports and a script that builds polyglot PDF/ELF payloads, indicating a proof‑of‑concept but no active exploitation or patch information.

    01020610
    4.7K followersView on X
  • SecureChap@SecureChap
    Exploit

    A click on a crafted PDF link in Evince executes attacker code through a 10-year-old bug. CVE-2026-46529 lives in ev_spawn() inside shell/ev-application.c. Three format strings pass destination values without g_shell_quote: --page-label=%s, --named-dest=%s, --find=%s. A /GoToR action supplies the string. Spaces in the value turn the command into new arguments. The attacker supplies --gtk-module pointing at a polyglot file that is both valid ELF and valid PDF. GTK3 loads it via dlopen; the constructor runs before the viewer finishes starting. The guard strcmp(application->uri, uri) is bypassed by appending ?1 to the filename. g_app_info_launch_uris still resolves the path correctly while the string comparison fails. The same code path affects Atril and Xreader. Patches landed in Evince 48.4, Atril 1.28.4, and Xreader 4.6.4. One format-string omission turned a document viewer into an ELF loader.

    Post summary

    The post details how a 10‑year‑old format‑string bug in Evince allows a crafted PDF to launch arbitrary code; the technique and impacted code paths are fully described, and patches are available for multiple viewers.

    00011146
    157 followersView on X
  • Ferramentas Linux@Cezar_H_Linux
    General

    ⚠️ ALERTA DE SEGURANÇA ⚠️ A vulnerabilidade CVE-2026-46529 no visualizador de PDFs Evince pode comprometer seu sistema com um único clique. Saiba mais. -> https://tinyurl.com/2xa5kyja #openSUSE https://t.co/0lVglr3xOn

    Post summary

    A brief security alert notes the presence of CVE-2026-46529 in the Evince PDF viewer and directs readers to a link for more information, but does not provide exploitation, PoC, or mitigation details.

    1000061
    1.5K followersView on X
  • N45HT@N45HTOfficial
    Exploit

    CVE-2026-46529: 10-year-old RCE in Linux PDF Viewer (XReader/Evince/Atril) by N1et 🤯🔥 👨‍💻 João Medeiros (N1et) 🔗 https://medeiros.zip/posts/CVE-2026-46529-evince 🔗 https://github.com/mate-desktop/atril/security/advisories/GHSA-vgv2-m826-8f6f 🔗 https://github.com/N1et/CVE-2026-46529 https://t.co/ypyr2MFEem

    Post summary

    The content announces a 10‑year‑old RCE in Linux PDF viewers, provides a PoC/exploit via links, but does not report active exploitation or patches.

    0000080
    93 followersView on X
  • Medeirus@jmedeiros1337
    General

    @mufeedvh @winfunction Cool! I started doing 0-day research with popular AIs too. This helped me find CVE-2026-46529, but I haven’t had much success with local models yet.

    Post summary

    The user reports discovering CVE-2026-46529 using AI, but provides no further details on exploitation, patches, or technical aspects.

    0000091
    58 followersView on X
  • Joel B.D.@darkshram
    Patch

    Disponibles nuevas versiones de Atril, Evince y Xreader que corrigen el CVE-2026-46529. vía @darkshram https://www.alcancelibre.org/noticias/disponibles-nuevas-versiones-de-atril-evince-y-xreader-que-corrigen-el-cve-2026-46529

    Post summary

    New releases of Atril, Evince and Xreader fixed CVE‑2026‑46529.

    00000107
    1.0K followersView on X

Explore more