AI analysis
The CVE-2026-91795 flaw in Foxit PDF Editor/Reader's FileOpen plugin enables chained read and write access violations and potentially arbitrary code execution. It is triggered by specially crafted PDF files that contain improperly validated encryption metadata. An attacker can gain full system or application control. The affected scope includes all Foxit PDF Editor/Reader installations, though exact versions and counts are unknown.
What to do: Upgrade all affected Foxit PDF Editor/Reader installations to the latest patched versions. Implement robust plugin security checks and enforce strict file validation for encryption metadata. Monitor for chained access issues and conduct regular security assessments.
Estimated exposure
—No basis for an estimate.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Foxit PDF Editor/Reader's FileOpen plugin did not adequately validate certain encryption metadata in specially crafted PDF files. This could leave an internal pointer in an invalid state, resulting in chained read and write access violations and potentially enabling arbitrary code execution.