Junglewise Threat Intelligence

CVE-2026-91794: Foxit PDF Editor out-of-bounds write in color space processing

CVE-2026-91794 · Severity: high · CVSS 7.8 · Published 2026-09-23

Technologies: Foxit PDF Reader, Foxit PDF Editor. Vendors: Foxit.

Executive brief

Foxit PDF Editor and Reader are widely used tools for viewing and editing PDF documents in corporate and personal environments. A flaw in how these applications process color space data in PDFs allows an attacker to craft a malicious document that, when opened, can crash the application or potentially execute arbitrary code on the victim's computer. An attacker could distribute such a document via email or a website to compromise user systems.

Technical details

An out-of-bounds write vulnerability (CWE-787) exists in the PDF rendering engine due to insufficient validation of color space data structures. The vulnerability is triggered when processing malformed color space entries during PDF parsing and rendering. An attacker can exploit this by crafting a specially crafted PDF document and requiring user interaction (opening the file); no authentication or network access is required.

Affected products

  • Foxit PDF Reader 2026.2.0.39747 and earlier
  • Foxit PDF Editor 2026.2.0.39747 and all previous 2026.x versions; 2025.3.0.35737 and all previous 2025.x versions; 2024.4.1.27687 and all previous 2024.x versions; 2023.3.0.23028 and all previous 2023.x versions; 14.0.7.33751 and all previous 14.x versions; 13.2.6.24111 and earlier

Timeline

  • 2026-09-23: disclosed: CVE-2026-91794 published
  • 2026-09-23: patched: Fixed in Foxit PDF Reader 2026.2.1 and Foxit PDF Editor 2026.2.1/14.0.8

References

Related threats