CVE-2026-46529: Evince/Atril/Xader command injection CVE-2026-46529
Published May 19, 2026
·Updated
Last updated 22 May 2026
Affected Software
7 affected componentsFixes available
Gnome Evince
MATE Atril
Xader
debian/atril<=1.24.0-1+deb11u1, <=1.26.0-2+deb12u3, <=1.26.2-4
1.24.0-1+deb11u21.28.4-1
debian/evince<=3.38.2-1, <=43.1-2, <=48.1-3
3.38.2-1+deb11u143.1-2+deb12u148.1-3+deb13u149~alpha-349~alpha.1-1
debian/evince-gtk3
48.4+dfsg-1
debian/papers<=48.3-1, <=49.3-2
49.3-3
Event History
May 23, 2026
CVE Published
via Ubuntu·02:51 PM
Data Sourced
via Ubuntu·02:51 PM
RemedyDescriptionSeverityAffected Software
Data Sourced
via Debian·02:52 PM
DescriptionAffected Software