{"id":"CVE-2026-91795","title":"Foxit PDF Editor/Reader's FileOpen plugin did not adequately validate certain encryption metadata in specially crafted PDF files","summary":"Foxit PDF Editor/Reader's FileOpen plugin did not adequately validate certain encryption metadata in specially crafted PDF files. This could leave an internal pointer in an invalid state, resulting in chained read and write access violat…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-822"],"vendor":"Foxit Software Inc.","product":"Foxit PDF Editor","affected":["foxit_pdf_editor Versions 2026.2 and earlier","foxit_pdf_editor Versions 14.0.7 and earlier","foxit_pdf_editor Versions 13.2.6 and earlier","foxit_pdf_reader Versions 2026.2 and earlier"],"published":"2026-09-23","updated":"2026-09-23","sourceUpdated":"2026-09-23T15:17:26.167","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-91795","references":[{"url":"https://www.foxit.com/support/security-bulletins.html","label":"14984358-7092-470d-8f34-ade47a7658a2"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-23T14:46:41.289496Z"},"epss":0.0012,"epssPercentile":0.02055,"ingestedAt":"2026-09-23T08:20:37.587Z","slug":"CVE-2026-91795","body":"## Overview\n\nFoxit PDF Editor/Reader's FileOpen plugin did not adequately validate certain encryption metadata in specially crafted PDF files. This could leave an internal pointer in an invalid state, resulting in chained read and write access violations and potentially enabling arbitrary code execution.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}