Junglewise Threat Intelligence

CVE-2026-91800: Foxit PDF Editor privilege escalation in installer on macOS

CVE-2026-91800 · Severity: high · CVSS 8.8 · Published 2026-09-23

Technologies: Foxit PDF Editor. Vendors: Foxit.

Executive brief

Foxit PDF Editor's macOS installer contains a local privilege escalation vulnerability that allows an attacker with local access to execute arbitrary commands with root privileges. An attacker could gain complete control of the system by exploiting insufficient validation of configuration values during software upgrades, potentially leading to data theft, malware installation, or system compromise.

Technical details

The vulnerability exists in the installer's upgrade mechanism due to insufficient validation of a user-modifiable configuration value that is processed with elevated privileges. A local, unauthenticated attacker can exploit this during high-privilege upgrade operations to execute arbitrary code as root. A patch is available in Foxit PDF Editor 2026.2.1 and later versions.

Affected products

  • Foxit PDF Editor 2026.2.0 and earlier, 2025.3.0 and earlier, 2024.4.1 and earlier, 2023.3.0 and earlier, 14.0.7 and earlier, 13.2.6 and earlier

Timeline

  • 2026-09-23: disclosed: CVE-2026-91800 published
  • 2026-09-23: patched: Foxit PDF Editor 2026.2.1 and 14.0.8 released

References

Related threats