Junglewise Threat Intelligence

CVE-2026-91803: Foxit PDF Editor privilege escalation in updater via DLL loading

CVE-2026-91803 · Severity: high · CVSS 8.8 · Published 2026-09-23

Technologies: Foxit PDF Reader, Foxit PDF Editor. Vendors: Foxit.

Executive brief

Foxit PDF Editor and Reader include an updater component that loads libraries from a user-writable directory during high-privilege operations, allowing a local attacker to execute code with administrator rights. An attacker with local access could exploit this to gain full system control and install malware or steal sensitive data.

Technical details

A DLL preloading/hijacking vulnerability exists in the updater process due to unsafe dynamic library loading from a world-writable directory during privileged operations. The vulnerability requires local access and no user interaction beyond the updater running at elevated privileges. Successful exploitation results in arbitrary code execution with the elevated privileges of the updater process.

Affected products

  • Foxit PDF Reader 2026.2.0.39747 and earlier on Windows
  • Foxit PDF Editor 2026.2.0.39747 and all prior 2026.x, 2025.3.0.35737 and all prior 2025.x, 2024.4.1.27687 and all prior 2024.x, 2023.3.0.23028 and all prior 2023.x, 14.0.7.33751 and all prior 14.x, 13.2.6.24111 and earlier on Windows

Timeline

  • 2026-09-23: disclosed: CVE-2026-91803 published and patches released
  • 2026-09-23: patched: Foxit PDF Reader 2026.2.1 and Foxit PDF Editor 2026.2.1/14.0.8 released

References

Related threats