CVE-2026-91805

Summary

A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s PDF page-tree handling. A specially crafted PDF can trigger page-structure changes during rendering, causing the application to access released page objects and resulting in memory corruption and an application crash.

Affected Software

VendorProductVersion RangeStatus
Foxit Software Inc.Foxit PDF EditorVersions 2026.2 and earlieraffected
Foxit Software Inc.Foxit PDF EditorVersions 14.0.7 and earlieraffected
Foxit Software Inc.Foxit PDF EditorVersions 13.2.6 and earlieraffected
Foxit Software Inc.Foxit PDF ReaderVersions 2026.2 and earlieraffected

Weaknesses

  • CWE-416: Use After Free (CWE-416)

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References