Junglewise Threat Intelligence

CVE-2026-91816: Foxit PDF Editor use-after-free in annotation handling

CVE-2026-91816 · Severity: high · CVSS 7.8 · Published 2026-09-23

Technologies: Foxit PDF Reader, Foxit PDF Editor. Vendors: Foxit.

Executive brief

Foxit PDF Editor and Reader contain a use-after-free vulnerability in how they handle PDF annotations when JavaScript code attempts to delete them. An attacker can craft a malicious PDF that triggers this flaw when opened, causing the application to crash or potentially allowing code execution. This affects both the popular free Reader and the professional Editor product used by organizations handling sensitive documents.

Technical details

A use-after-free vulnerability exists in the annotation deletion logic, triggered by reentrant JavaScript calls that attempt to delete annotation objects. When JavaScript code deletes an annotation during processing, the application may continue to access the freed annotation object, leading to memory corruption. The attack requires user interaction (opening a crafted PDF) and no authentication.

Affected products

  • Foxit PDF Reader 2026.2.0.39747 and earlier
  • Foxit PDF Editor 2026.2.0.39747 and all previous 2026.x versions, 2025.3.0.35737 and all previous 2025.x versions, 2024.4.1.27687 and all previous 2024.x versions, 2023.3.0.23028 and all previous 2023.x versions, 14.0.7.33751 and all previous 14.x versions, 13.2.6.24111 and earlier

Timeline

  • 2026-09-23: disclosed: Vulnerability disclosed and patched versions released
  • 2026-09-23: patched: Fixed in Foxit PDF Reader 2026.2.1 and Foxit PDF Editor 2026.2.1/14.0.8

References

Related threats