CVE-2026-91797

Summary

Foxit PDF Editor/Reader failed to validate the directory traversal path in the attachment file name, resulting in malicious attachments being able to be written to directories outside the expected secure area when the PDF is opened.

Affected Software

VendorProductVersion RangeStatus
Foxit Software Inc.Foxit PDF EditorVersions 2026.2 and earlieraffected
Foxit Software Inc.Foxit PDF EditorVersions 14.0.7 and earlieraffected
Foxit Software Inc.Foxit PDF EditorVersions 13.2.6 and earlieraffected
Foxit Software Inc.Foxit PDF ReaderVersions 2026.2 and earlieraffected

Weaknesses

  • CWE-73: CWE-73 External control of file name or path

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References