CVE-2026-46529: Mate-Desktop Atril
High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.
Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote code execution vulnerability in versions prior to 1.26.3 and 1.28.4 allows an attacker to achieve arbitrary code execution as the user by tricking them into clicking a link inside a malicious PDF document. The PDF can be packaged as a polyglot file that is simultaneously a valid PDF and a valid ELF shared library, making the attack a single-file, single-click, configuration-independent RCE on stock atril installations. The root cause is `shell/ev-application.c:ev_spawn`, which builds a command line from attacker-controlled PDF link-destination fields without applying `g_shell_quote`. The cmdline is then handed to `g_app_info_create_from_commandline`, which shell-parses it back into argv — splitting any embedded `--gtk-module=PATH` into a separate argv element. GTK then `dlopen()`s the path during init, running any `__attribute__((constructor))` it finds. Versions 1.26.3 and 1.28.4 contain a patch for the issue. This is the same defect class as CVE-2023-51698 (CBT `--checkpoint-action` injection in `comics-document.c`, fixed in 1.6.2) but in a different code path (`shell/ev-application.c`) that the original patch did not touch.
Affected products
- Mate-Desktop Atril: before 1.26.3 (fixed in 1.26.3); from 1.27.0, before 1.28.4 (fixed in 1.28.4)
- Red Hat Red Hat Enterprise Linux 6
- Red Hat Red Hat Enterprise Linux 7 Extended Lifecycle Support: before 0:3.28.2-11.el7_9 (fixed in 0:3.28.2-11.el7_9)
- Red Hat Red Hat Enterprise Linux 8: before 0:3.28.4-17.el8_10 (fixed in 0:3.28.4-17.el8_10)
- Red Hat Red Hat Enterprise Linux 8.4 Advanced Mission Critical Update Support: before 0:3.28.4-11.el8_4.1 (fixed in 0:3.28.4-11.el8_4.1)
- Red Hat Red Hat Enterprise Linux 8.4 Extended Update Support Long-Life Add-On: before 0:3.28.4-11.el8_4.1 (fixed in 0:3.28.4-11.el8_4.1)
- Red Hat Red Hat Enterprise Linux 8.6 Advanced Mission Critical Update Support: before 0:3.28.4-16.el8_6.1 (fixed in 0:3.28.4-16.el8_6.1)
- Red Hat Red Hat Enterprise Linux 8.6 Extended Update Support Long-Life Add-On: before 0:3.28.4-16.el8_6.1 (fixed in 0:3.28.4-16.el8_6.1)
- Red Hat Red Hat Enterprise Linux 8.8 Telecommunications Update Service: before 0:3.28.4-16.el8_8.1 (fixed in 0:3.28.4-16.el8_8.1)
- Red Hat Red Hat Enterprise Linux 8.8 Update Services For SAP Solutions: before 0:3.28.4-16.el8_8.1 (fixed in 0:3.28.4-16.el8_8.1)
- Red Hat Red Hat Enterprise Linux 9: before 0:40.5-4.el9_8.1 (fixed in 0:40.5-4.el9_8.1)
- Red Hat Red Hat Enterprise Linux 9.2 Update Services For SAP Solutions: before 0:40.5-2.el9_2.1 (fixed in 0:40.5-2.el9_2.1)
- Red Hat Red Hat Enterprise Linux 9.4 Update Services For SAP Solutions: before 0:40.5-2.el9_4.1 (fixed in 0:40.5-2.el9_4.1)
- Red Hat Red Hat Enterprise Linux 9.6 Extended Update Support: before 0:40.5-2.el9_6.1 (fixed in 0:40.5-2.el9_6.1)
Published 2026-06-10. Last modified 2026-07-28.