Out-of-Bounds Write Vulnerability in Foxit PDF Editor and Reader
CVE-2026-91815

7.8HIGH

Key Information:

Vendor

Foxit Inc.

Vendor
CVE Published:
23 September 2026

What is CVE-2026-91815?

Foxit PDF Editor and Reader have a significant vulnerability stemming from inadequate validation of JPEG2000 image metadata within PDF files. This flaw allows for out-of-bounds writes in the heap memory during the decoding process. An attacker could exploit this vulnerability to crash the application or potentially execute arbitrary code, posing serious risks to users' systems and data integrity. Users are advised to apply the necessary patches and security updates to mitigate this risk.

Affected Version(s)

Foxit PDF Editor Windows Versions 2026.2 and earlier

Foxit PDF Editor Windows Versions 14.0.7 and earlier

Foxit PDF Editor Windows Versions 13.2.6 and earlier

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

06fe5fd2bc53027c4a3b7e395af0b850e7b8a044 working with TrendAI Zero Day Initiative
.