Junglewise Threat Intelligence

CVE-2026-91799: Foxit PDF Editor use-after-free in JavaScript array handling

CVE-2026-91799 · Severity: high · CVSS 7.8 · Published 2026-09-23

Technologies: Foxit PDF Reader, Foxit PDF Editor. Vendors: Foxit.

Executive brief

Foxit PDF Editor and Reader are widely-used document processing applications. A use-after-free vulnerability in how they handle JavaScript arrays in PDF files can allow attackers to trigger application crashes or potentially execute arbitrary code by crafting a malicious PDF. No active exploitation has been reported as of the disclosure date.

Technical details

A use-after-free vulnerability exists in JavaScript array object processing where the application accesses a released object during array operations. The vulnerability is triggered by opening a specially crafted PDF file, requiring only user interaction (opening the file) with no special privileges. Successful exploitation can lead to code execution or application denial of service; patches are available in reader version 2026.2.1 and editor versions 2026.2.1/14.0.8 and later.

Affected products

  • Foxit PDF Reader 2026.2.0.39747 and earlier
  • Foxit PDF Editor 2026.2.0.39747 and all previous 2026.x, 2025.3.0.35737 and all previous 2025.x, 2024.4.1.27687 and all previous 2024.x, 2023.3.0.23028 and all previous 2023.x, 14.0.7.33751 and all previous 14.x, 13.2.6.24111 and earlier

Timeline

  • 2026-09-23: disclosed
  • 2026-09-23: patched: PDF Reader 2026.2.1 and PDF Editor 2026.2.1/14.0.8 released

References

Related threats