Memory Allocation Flaw in Foxit PDF Editor/Reader Affects Image Processing
CVE-2026-91789

7.8HIGH

Key Information:

Vendor

Foxit Inc.

Vendor
CVE Published:
23 September 2026

What is CVE-2026-91789?

A flaw in Foxit PDF Editor and Reader's U3D/GIF texture decoding process has been identified, stemming from inadequate validation of image dimensions and size information. Exploiting this vulnerability can lead to improper memory allocation and an out-of-bounds write situation during pixel processing, which may allow remote attackers to execute arbitrary code on the affected system.

Affected Version(s)

Foxit PDF Editor Windows Versions 2026.2 and earlier

Foxit PDF Editor Windows Versions 14.0.7 and earlier

Foxit PDF Editor Windows Versions 13.2.6 and earlier

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Liang Zhu working with TrendAI Zero Day Initiative
.