CVE-2025-15569 HIGH

CVE-2025-15569: Artifex MuPDF win_main.c get_system_dpi uncontrolled search path

Vendor Artifex
Product MuPDF
Weakness CWE-427
Published February 10, 2026
Last update February 23, 2026

CVSS base score

7.3/10
Attack vector Local
Attack complexity High
Privileges required Low
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X

What the vulnerability does

01Description

A flaw has been found in Artifex MuPDF up to 1.26.1 on Windows. The impacted element is the function get_system_dpi of the file platform/x11/win_main.c. This manipulation causes uncontrolled search path. The attack requires local access. The attack is considered to have high complexity. The exploitability is regarded as difficult. Upgrading to version 1.26.2 is sufficient to resolve this issue. Patch name: ebb125334eb007d64e579204af3c264aadf2e244. Upgrading the affected component is recommended.

Key dates

02Disclosure timeline

February 10, 2026 CVE published
February 23, 2026 Record updated