PT-2026-97232 · Foxit · Foxit Pdf Reader+1

CVE-2026-91813

·

Published

2026-09-23

·

Updated

2026-09-23

CVSS v3.1

8.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Foxit PDF Editor/Reader (affected versions not specified)
Description A race condition exists in the update mechanism of Foxit PDF Editor/Reader. Due to insufficient file locking and integrity validation, an update package can be replaced by a local attacker between the time it is downloaded and when it is extracted with high privileges. This flaw allows for local privilege escalation, enabling the execution of arbitrary code with elevated privileges.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

LPE

Time Of Check To Time Of Use

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-91813
ZDI-26-742

Affected Products

Foxit Pdf Editor
Foxit Pdf Reader