---
id: CVE-2026-91795
title: >-
  Foxit PDF Editor/Reader's FileOpen plugin did not adequately validate certain
  encryption metadata in specially crafted PDF files
summary: >-
  Foxit PDF Editor/Reader's FileOpen plugin did not adequately validate certain
  encryption metadata in specially crafted PDF files. This could leave an
  internal pointer in an invalid state, resulting in chained read and write
  access violat…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-822
vendor: Foxit Software Inc.
product: Foxit PDF Editor
affected:
  - foxit_pdf_editor Versions 2026.2 and earlier
  - foxit_pdf_editor Versions 14.0.7 and earlier
  - foxit_pdf_editor Versions 13.2.6 and earlier
  - foxit_pdf_reader Versions 2026.2 and earlier
published: '2026-09-23'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T17:58:26.570'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-91795'
references:
  - url: 'https://www.foxit.com/support/security-bulletins.html'
    label: 14984358-7092-470d-8f34-ade47a7658a2
tags:
  - nvd
  - cve.org
epss: 0.00085
epssPercentile: 0.00272
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-23T14:46:41.289496Z'
ingestedAt: '2026-09-23T08:20:37.587Z'
---

## Overview

Foxit PDF Editor/Reader's FileOpen plugin did not adequately validate certain encryption metadata in specially crafted PDF files. This could leave an internal pointer in an invalid state, resulting in chained read and write access violations and potentially enabling arbitrary code execution.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
