ZDI-26-724: Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability
ZDI disclosed a Foxit PDF Reader annotation use-after-free that allows remote code execution.
The Zero Day Initiative published ZDI-26-724, a use-after-free in Foxit PDF Reader annotation handling tracked as CVE-2026-91792. ZDI assigned CVSS 7.8 and says a remote attacker can execute arbitrary code if a user opens a malicious file or visits a malicious page. The advisory does not say the flaw is being exploited.
- CVE-2026-91792 is an annotation use-after-free in Foxit PDF Reader.
- ZDI rates the remote code execution flaw CVSS 7.8.
- Exploitation requires opening a malicious file or visiting a malicious page.
- No observed exploitation is stated in the advisory.
Vulnerabilities mentionedAll →
- CVE-2026-917927.8—Reentrant Zoom RCE in Foxit PDF Editor/Reader 5.0+ (CVE-2026-91792)published · Foxit PDF Editor/Reader
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-91792 | Reentrant Zoom RCE in Foxit PDF Editor/Reader 5.0+ (CVE-2026-91792) Foxit PDF Editor/Reader can execute reentrant zoom and layout operations through page- and annotation-related JavaScript actions when processing specially crafted PDFs. This vulnerability allows the application to access page objects that have been released, triggering a use-after-free condition and causing an application crash. An attacker can potentially gain unauthorized access and privileges, and could leverage the vulnerability to exfiltrate data or perform other malicious actions. The affected products are Foxit PDF Editor/Reader, and the current exploitation status is none known. Do: Upgrade to the latest version of Foxit PDF Editor/Reader; disable reentrant zoom and layout operations; monitor page/annotation JS actions; verify no page objects are released before use. |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91792.
This source does not provide full text. Read it at zerodayinitiative.com.