CVE-2026-91801

Summary

A path traversal vulnerability exists in Foxit PDF Editor/Reader's handling of embedded PDF resources. Insufficient validation of resource file paths may allow files to be written outside their intended locations, potentially enabling arbitrary code execution.

Affected Software

VendorProductVersion RangeStatus
Foxit Software Inc.Foxit PDF EditorVersions 2026.2 and earlieraffected
Foxit Software Inc.Foxit PDF EditorVersions 14.0.7 and earlieraffected
Foxit Software Inc.Foxit PDF EditorVersions 13.2.6 and earlieraffected
Foxit Software Inc.Foxit PDF ReaderVersions 2026.2 and earlieraffected

Weaknesses

  • CWE-22: CWE-22: Improper Limitation of a Pathname to a Restricted Directory

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References