ZDI-26-743: Foxit PDF Reader JPEG2000 Parsing Memory Corruption Remote Code Execution Vulnerability
Foxit PDF Reader JPEG2000 parsing bug CVE-2026-91815 can yield remote code execution after user interaction.
ZDI-26-743 describes a JPEG2000 parsing memory-corruption vulnerability in Foxit PDF Reader that can lead to remote code execution. A user must open a malicious file or visit a malicious page. ZDI assigned CVSS 7.8 and CVE-2026-91815. Exploitation in the wild is not reported.
- Memory corruption occurs while parsing JPEG2000 content.
- Exploitation needs a user to open a malicious file or page.
- Tracked as CVE-2026-91815 with CVSS 7.8.
- No in-the-wild exploitation is stated.
Vulnerabilities mentionedAll →
- CVE-2026-918157.8—JPEG2000 Metadata Verification Vulnerability in Foxit PDF Editor/Readerpublished · Foxit PDF Editor/Reader
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-91815 | JPEG2000 Metadata Verification Vulnerability in Foxit PDF Editor/Reader Foxit PDF Editor/Reader lacks sufficient verification of JPEG2000 image metadata in PDF files, enabling an out-of-bounds write in the heap buffer during decoding. This flaw can cause the program to crash and introduces the risk of arbitrary code execution. An attacker can potentially gain elevated privileges and execute arbitrary code on affected systems. The affected products are Foxit PDF Editor/Reader, with no known public exploits. Do: Upgrade to patched versions of Foxit PDF Editor/Reader. Implement image metadata verification and JPEG2000 decoding safeguards. Monitor for heap buffer overflow signs and enforce input validation. |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91815.
This source does not provide full text. Read it at zerodayinitiative.com.