ZDI-26-731: Foxit PDF Reader FileOpen Uninitialized Variable Remote Code Execution Vulnerability
Foxit PDF Reader FileOpen flaw CVE-2026-91795 allows remote code execution if a user opens a malicious file.
ZDI-26-731 discloses an uninitialized-variable flaw in Foxit PDF Reader's FileOpen handling that can let a remote attacker execute arbitrary code. The victim must open a malicious file or visit a malicious page. ZDI assigned CVSS 7.8 and CVE-2026-91795. The advisory does not report exploitation in the wild.
- ZDI-26-731 covers an uninitialized variable in FileOpen handling.
- Remote code execution requires opening a malicious file or page.
- ZDI rates the issue CVSS 7.8 as CVE-2026-91795.
- No active exploitation is reported.
Vulnerabilities mentionedAll →
- CVE-2026-917957.8—RCE via FileOpen Plugin in Foxit PDF Editor/Readerpublished · Foxit PDF Editor/Reader
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-91795 | RCE via FileOpen Plugin in Foxit PDF Editor/Reader The CVE-2026-91795 flaw in Foxit PDF Editor/Reader's FileOpen plugin enables chained read and write access violations and potentially arbitrary code execution. It is triggered by specially crafted PDF files that contain improperly validated encryption metadata. An attacker can gain full system or application control. The affected scope includes all Foxit PDF Editor/Reader installations, though exact versions and counts are unknown. Do: Upgrade all affected Foxit PDF Editor/Reader installations to the latest patched versions. Implement robust plugin security checks and enforce strict file validation for encryption metadata. Monitor for chained access issues and conduct regular security assessments. |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91795.
This source does not provide full text. Read it at zerodayinitiative.com.