CVE-2026-91792

Summary

When processing a specially crafted PDF, Foxit PDF Editor/Reader may perform reentrant zoom and layout operations through page- and annotation-related JavaScript actions. This can cause the application to access page objects after they have been released, resulting in a use-after-free condition and an application crash.

Affected Software

VendorProductVersion RangeStatus
Foxit Software Inc.Foxit PDF EditorVersions 2026.2 and earlieraffected
Foxit Software Inc.Foxit PDF EditorVersions 14.0.7 and earlieraffected
Foxit Software Inc.Foxit PDF EditorVersions 13.2.6 and earlieraffected
Foxit Software Inc.Foxit PDF ReaderVersions 2026.2 and earlieraffected

Weaknesses

  • CWE-416: CWE-416 Use after free

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References