CVE-2026-91795
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
Foxit PDF Editor/Reader's FileOpen plugin did not adequately validate certain encryption metadata in specially crafted PDF files. This could leave an internal pointer in an invalid state, resulting in chained read and write access violations and potentially enabling arbitrary code execution.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Foxit Software Inc. | Foxit PDF Editor | Versions 2026.2 and earlier | affected |
| Foxit Software Inc. | Foxit PDF Editor | Versions 14.0.7 and earlier | affected |
| Foxit Software Inc. | Foxit PDF Editor | Versions 13.2.6 and earlier | affected |
| Foxit Software Inc. | Foxit PDF Reader | Versions 2026.2 and earlier | affected |
Weaknesses
- CWE-822: CWE-822 Untrusted pointer dereference
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.