ZDI-26-720: Foxit PDF Reader activeDocs Missing Authorization Information Disclosure Vulnerability
Foxit PDF Reader activeDocs flaw can leak information if a user opens a malicious file.
ZDI advisory ZDI-26-720 describes a missing authorization issue in Foxit PDF Reader's activeDocs feature that can disclose sensitive information. Exploitation requires the victim to open a malicious file or visit a malicious page. ZDI assigned CVSS 4.7 and CVE-2026-91788. Active exploitation is not mentioned.
- ZDI-26-720 is a missing-authorization flaw in Foxit PDF Reader activeDocs.
- Attackers can disclose sensitive information after user interaction.
- ZDI rated the issue CVSS 4.7; CVE-2026-91788 is assigned.
- No in-the-wild exploitation is reported.
Vulnerabilities mentionedAll →
- CVE-2026-917884.7—Missing JavaScript Authorization in Foxit PDF Editor/Reader Exposes Other Open PDFspublished · Foxit PDF Editor
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-91788 | Missing JavaScript Authorization in Foxit PDF Editor/Reader Exposes Other Open PDFs Foxit PDF Editor and Foxit PDF Reader fail to enforce the attribute-level authorization checks required by the PDF JavaScript specification, in the area of the activeDocs interface. When a victim opens a malicious PDF that is treated as trusted, its embedded JavaScript can read sensitive content from other documents open in the same process and transmit that data to an external party. The impact is confidentiality-only (high confidentiality impact, no integrity or availability impact), and exploitation requires user interaction with high attack complexity, limiting its practical severity to medium (CVSS 4.7). Anyone running an unpatched Foxit PDF Editor or Reader on Windows or other supported desktop platforms is affected. There is no known public proof of concept, and the flaw is not on the CISA Known Exploited Vulnerabilities list. |
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 4.7. The following CVEs are assigned: CVE-2026-91788.
This source does not provide full text. Read it at zerodayinitiative.com.