Junglewise Threat Intelligence

CVE-2026-91813: Foxit PDF Reader/Editor update mechanism privilege escalation

CVE-2026-91813 · Severity: high · CVSS 8.8 · Published 2026-09-23

Technologies: Foxit PDF Reader, Foxit PDF Editor. Vendors: Foxit.

Executive brief

Foxit PDF Reader and PDF Editor contain a vulnerability in their automatic update mechanism that allows a local attacker to replace update packages with malicious code before the application extracts and executes them with elevated privileges. An attacker with local access could exploit this to gain administrative control of the system or execute arbitrary commands.

Technical details

The vulnerability stems from insufficient file locking and integrity validation during the update process, allowing a time-of-check-time-of-use (TOCTOU) race condition where an attacker can swap the update package between download and extraction. The flaw requires local system access and affects the Windows update mechanism, enabling arbitrary code execution with the privileges of the PDF application process.

Affected products

  • Foxit PDF Reader 2026.2.0.39747 and earlier
  • Foxit PDF Editor 2026.2.0.39747 and all previous 2026.x versions, 2025.3.0.35737 and all previous 2025.x versions, 2024.4.1.27687 and all previous 2024.x versions, 2023.3.0.23028 and all previous 2023.x versions, 14.0.7.33751 and all previous 14.x versions, 13.2.6.24111 and earlier

Timeline

  • 2026-09-23: disclosed: CVE-2026-91813 published on NVD
  • 2026-09-23: patched: Foxit PDF Reader 2026.2.1 and Foxit PDF Editor 2026.2.1/14.0.8 released

References

Related threats