Junglewise Threat Intelligence

CVE-2026-91811: Foxit PDF Reader heap out-of-bounds write in PRC parser

CVE-2026-91811 · Severity: high · CVSS 7.8 · Published 2026-09-23

Technologies: Foxit PDF Reader, Foxit PDF Editor. Vendors: Foxit.

Executive brief

Foxit PDF Reader and Editor are desktop applications used to view and edit PDF documents. A flaw in how these products parse PRC (Product Representation Compact) 3D model files can cause a crash or potentially allow an attacker to execute code by crafting a malicious PDF or 3D model file. An attacker would need to trick a user into opening a specially crafted file.

Technical details

A heap-based out-of-bounds write vulnerability exists in the PRC parser due to insufficient validation of vertex indices in triangular fan texture meshes (CWE-787). The flaw is triggered when processing malformed PRC data embedded in PDF files or 3D content. Exploitation requires user interaction to open a crafted file and can result in memory corruption, denial of service, or code execution.

Affected products

  • Foxit PDF Reader 2026.2.0.39747 and earlier
  • Foxit PDF Editor 2026.2.0.39747 and all previous 2026.x versions, 2025.3.0.35737 and all previous 2025.x versions, 2024.4.1.27687 and all previous 2024.x versions, 2023.3.0.23028 and all previous 2023.x versions, 14.0.7.33751 and all previous 14.x versions, 13.2.6.24111 and earlier

Timeline

  • 2026-09-23: disclosed
  • 2026-09-23: patched: Foxit PDF Reader 2026.2.1 and Foxit PDF Editor 2026.2.1/14.0.8

References

Related threats