Executive brief
Foxit PDF Editor and Reader, widely used document tools in enterprises, contain a flaw in the FileOpen plugin that fails to properly validate encryption metadata in specially crafted PDF files. An attacker who tricks a user into opening a malicious PDF can exploit this to execute arbitrary code on the victim's computer, potentially leading to data theft or system compromise.
Technical details
The FileOpen plugin inadequately validates encryption metadata in PDF files, leaving internal pointers in an invalid state and enabling chained read and write access violations. This local attack requires user interaction (opening a PDF) and can result in arbitrary code execution through memory corruption. The vulnerability is tracked as CVE-2026-91795 and is fixed in the patched versions released on September 23, 2026.
Affected products
- Foxit PDF Reader 2026.2.0.39747 and earlier
- Foxit PDF Editor 2026.2.0.39747 and all previous 2026.x versions, 2025.3.0.35737 and all previous 2025.x versions, 2024.4.1.27687 and all previous 2024.x versions, 2023.3.0.23028 and all previous 2023.x versions, 14.0.7.33751 and all previous 14.x versions, 13.2.6.24111 and earlier
Timeline
- 2026-09-23: disclosed: Security bulletin and patch release
- 2026-09-23: patched: Fixed in PDF Reader 2026.2.1 and PDF Editor 2026.2.1/14.0.8