CVE-2026-91797
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Summary
Foxit PDF Editor/Reader failed to validate the directory traversal path in the attachment file name, resulting in malicious attachments being able to be written to directories outside the expected secure area when the PDF is opened.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Foxit Software Inc. | Foxit PDF Editor | Versions 2026.2 and earlier | affected |
| Foxit Software Inc. | Foxit PDF Editor | Versions 14.0.7 and earlier | affected |
| Foxit Software Inc. | Foxit PDF Editor | Versions 13.2.6 and earlier | affected |
| Foxit Software Inc. | Foxit PDF Reader | Versions 2026.2 and earlier | affected |
Weaknesses
- CWE-73: CWE-73 External control of file name or path
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: total
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.