ZDI-26-730: Foxit PDF Reader DeviceN Colorspace Out-Of-Bounds Write Remote Code Execution Vulnerability
Foxit PDF Reader DeviceN out-of-bounds write can enable remote code execution after user interaction.
ZDI published ZDI-26-730, an out-of-bounds write in Foxit PDF Reader's DeviceN colorspace processing. A remote attacker can execute arbitrary code if the user opens a crafted file or visits a malicious page. The issue is tracked as CVE-2026-91794 with a ZDI CVSS score of 7.8. Exploitation in the wild is not reported.
- ZDI-26-730 is an out-of-bounds write in Foxit PDF Reader DeviceN colorspace handling.
- The flaw can lead to remote code execution.
- User interaction is required via a malicious page or file.
- ZDI rated it CVSS 7.8 under CVE-2026-91794.
Vulnerabilities mentionedAll →
- CVE-2026-917947.8—Out-of-bounds RCE in Foxit PDF Editor/Reader due to Malformed Color Space Datapublished · Foxit PDF Editor/Reader
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-91794 | Out-of-bounds RCE in Foxit PDF Editor/Reader due to Malformed Color Space Data This vulnerability is an out-of-bounds write in the PDF rendering process of Foxit PDF Editor/Reader caused by insufficient consistency and boundary validation of malformed color space data. It can trigger program crashes and may enable remote code execution, presenting a high risk to system integrity. An attacker could exploit this flaw to gain unauthorized access and perform malicious actions, potentially affecting users or devices with the affected product. Currently, there is no known public exploit, and the vulnerability has not yet been actively exploited. Do: Upgrade to the latest version of Foxit PDF Editor/Reader; implement robust color space validation and boundary checks; monitor for out-of-bounds write issues and malformed input handling; verify PDF rendering process security and test for potential RCE risks. |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91794.
This source does not provide full text. Read it at zerodayinitiative.com.