Junglewise Threat Intelligence

CVE-2026-91815: Foxit PDF Editor/Reader out-of-bounds write in JPEG2000 decoding

CVE-2026-91815 · Severity: high · CVSS 7.8 · Published 2026-09-23

Technologies: Foxit PDF Reader, Foxit PDF Editor. Vendors: Foxit.

Executive brief

Foxit PDF Editor and Reader fail to properly validate JPEG2000 image metadata when processing PDF files, allowing an attacker to craft a malicious PDF that triggers a heap buffer overflow during image decoding. This can crash the application or potentially allow arbitrary code execution if the user opens the malicious PDF.

Technical details

The vulnerability is an out-of-bounds write (CWE-787) in the JPEG2000 image decoder, caused by insufficient validation of image metadata before heap buffer operations. The attack vector is local and requires user interaction (opening a malicious PDF). An attacker can achieve code execution or denial of service via a specially crafted PDF file.

Affected products

  • Foxit PDF Reader 2026.2.0.39747 and earlier
  • Foxit PDF Editor 2026.2.0.39747 and all previous 2026.x, 2025.3.0.35737 and all previous 2025.x, 2024.4.1.27687 and all previous 2024.x, 2023.3.0.23028 and all previous 2023.x, 14.0.7.33751 and all previous 14.x, 13.2.6.24111 and earlier

Timeline

  • 2026-09-23: disclosed: Security bulletin released by Foxit with fixes in PDF Reader 2026.2.1 and PDF Editor 2026.2.1/14.0.8
  • 2026-09-23: patched: Fixed in PDF Reader 2026.2.1 and PDF Editor 2026.2.1/14.0.8

References

Related threats