---
id: CVE-2026-91797
title: >-
  Foxit PDF Editor/Reader failed to validate the directory traversal path in the
  attachment file name, resulting in malicious attachments being able to be
  written to directories outside the expected secure area when the PDF is
  opened.
summary: >-
  Foxit PDF Editor/Reader failed to validate the directory traversal path in the
  attachment file name, resulting in malicious attachments being able to be
  written to directories outside the expected secure area when the PDF is
  opened.
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'
cwe:
  - CWE-73
vendor: Foxit Software Inc.
product: Foxit PDF Editor
affected:
  - foxit_pdf_editor Versions 2026.2 and earlier
  - foxit_pdf_editor Versions 14.0.7 and earlier
  - foxit_pdf_editor Versions 13.2.6 and earlier
  - foxit_pdf_reader Versions 2026.2 and earlier
published: '2026-09-23'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T17:58:26.570'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-91797'
references:
  - url: 'https://www.foxit.com/support/security-bulletins.html'
    label: 14984358-7092-470d-8f34-ade47a7658a2
tags:
  - nvd
  - cve.org
epss: 0.00346
epssPercentile: 0.2824
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-23T15:25:36.693438Z'
ingestedAt: '2026-09-23T08:20:37.588Z'
---

## Overview

Foxit PDF Editor/Reader failed to validate the directory traversal path in the attachment file name, resulting in malicious attachments being able to be written to directories outside the expected secure area when the PDF is opened.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
