JPEG2000 Metadata Verification Vulnerability in Foxit PDF Editor/Reader
CVSS 3.1
7.8high
EPSS
—
Published
()
Modified
AI analysis
Foxit PDF Editor/Reader lacks sufficient verification of JPEG2000 image metadata in PDF files, enabling an out-of-bounds write in the heap buffer during decoding. This flaw can cause the program to crash and introduces the risk of arbitrary code execution. An attacker can potentially gain elevated privileges and execute arbitrary code on affected systems. The affected products are Foxit PDF Editor/Reader, with no known public exploits.
What to do: Upgrade to patched versions of Foxit PDF Editor/Reader. Implement image metadata verification and JPEG2000 decoding safeguards. Monitor for heap buffer overflow signs and enforce input validation.
Affected
Foxit PDF Editor/Reader
—
Estimated exposure
moderatemoderate (10k-100k systems) — Based on high CVSS and public vulnerability analysis, affected products are Foxit PDF Editor/Reader; exposure is estimated at a moderate order of magnitude based on high-impact nature and likely widespread deployment patterns.
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Description
Foxit PDF Editor/Reader does not perform sufficient verification of the JPEG2000 image metadata in the PDF file, which leads to out-of-bounds write in the heap buffer during decoding, potentially causing the program to crash and introducing the risk of arbitrary code execution.
Foxit PDF Reader JPEG2000 parsing bug CVE-2026-91815 can yield remote code execution after user interaction.
ZDI-26-743 describes a JPEG2000 parsing memory-corruption vulnerability in Foxit PDF Reader that can lead to remote code execution. A user must open a malicious file or visit a malicious page. ZDI assigned CVSS 7.8 and CVE-2026-91815. Exploitation in the wild is not reported.