← back
CVE-2026-91795highCWE-822

Foxit PDF Editor/Reader FileOpen Uninitialized Variable Remote Code Execution Vulnerability

18Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 7.8
exploitation probability
observed exploitation
nono source reports it
Foxit PDF Editor/Reader's FileOpen plugin did not adequately validate certain encryption metadata in specially crafted PDF files. This could leave an internal pointer in an invalid state, resulting in chained read and write access violations and potentially enabling arbitrary code execution.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H