ZDI-26-742: Foxit PDF Reader FoxitUpdater Race Condition Local Privilege Escalation Vulnerability
FoxitUpdater race condition CVE-2026-91813 lets a local low-privileged attacker escalate privileges on Foxit PDF Reader.
ZDI-26-742 discloses a race condition in Foxit PDF Reader's FoxitUpdater that allows local privilege escalation. An attacker must already be able to run low-privileged code on the target. ZDI assigned CVSS 7.8 and CVE-2026-91813. No in-the-wild exploitation is reported.
- Race condition is in the FoxitUpdater component.
- An attacker already needs low-privileged local code execution.
- Successful exploitation escalates privileges on the system.
- CVE-2026-91813 is rated CVSS 7.8; no wild exploitation reported.
Vulnerabilities mentionedAll →
- CVE-2026-918138.8—Local RCE in Foxit PDF Editor/Reader Update Mechanism 5.0+ (CVE-2026-91813)published · Foxit PDF Editor/Reader
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-91813 | Local RCE in Foxit PDF Editor/Reader Update Mechanism 5.0+ (CVE-2026-91813) A vulnerability in Foxit PDF Editor/Reader’s update mechanism allows an update package to be replaced between download and extraction due to insufficient file locking and integrity validation. This flaw enables local attackers to execute arbitrary code with elevated privileges. The affected product is Foxit PDF Editor/Reader, with no specific version range provided in the data. The exploitation status is currently unknown, as no public exploit has been disclosed. Do: Upgrade to the latest version of Foxit PDF Editor/Reader to mitigate the flaw. Implement robust file locking and integrity validation mechanisms to prevent unauthorized updates. Regularly audit and monitor for potential exploitation risks. |
This vulnerability allows local attackers to escalate privileges on affected installations of Foxit PDF Reader. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91813.
This source does not provide full text. Read it at zerodayinitiative.com.