ZDI-26-742: Foxit PDF Reader FoxitUpdater Race Condition Local Privilege Escalation Vulnerability
FoxitUpdater race condition CVE-2026-91813 lets a local low-privileged attacker escalate privileges on Foxit PDF Reader.
ZDI-26-742 discloses a race condition in Foxit PDF Reader's FoxitUpdater that allows local privilege escalation. An attacker must already be able to run low-privileged code on the target. ZDI assigned CVSS 7.8 and CVE-2026-91813. No in-the-wild exploitation is reported.