CVE-2026-91803
Received Received - Intake

Privilege Escalation in Foxit PDF Editor/Reader

Vulnerability report for CVE-2026-91803, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-23

Last updated on: 2026-09-23

Assigner: Foxit

Description

A local privilege escalation vulnerability exists in the updater of Foxit PDF Editor/Reader due to unsafe loading of dynamic-link libraries from a user-writable directory during high-privilege operations. A local attacker could exploit this issue to execute code with elevated privileges.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-23
Last Modified
2026-09-23
Generated
2026-09-23
AI Q&A
2026-09-23
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
foxit pdf_editor *
foxit pdf_reader *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-427 The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a local privilege escalation vulnerability in Foxit PDF Editor/Reader's updater. It occurs because the updater loads dynamic-link libraries from a user-writable directory during high-privilege operations. An attacker with local access could exploit this to run code with elevated privileges.

Impact Analysis

If exploited, this vulnerability could allow an attacker to gain higher-level permissions on your system. This might let them install malicious software, access sensitive data, or perform other unauthorized actions with the privileges of a privileged user.

Mitigation Strategies

Update Foxit PDF Editor/Reader to the latest version to patch the vulnerability. Ensure the updater no longer loads dynamic-link libraries from user-writable directories during high-privilege operations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-91803. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart