ZDI-26-733: Foxit PDF Reader Portfolio Directory Traversal Remote Code Execution Vulnerability
ZDI disclosed a Foxit PDF Reader portfolio directory traversal that can lead to remote code execution.
The Zero Day Initiative published ZDI-26-733, a directory-traversal flaw in Foxit PDF Reader portfolio handling tracked as CVE-2026-91797. ZDI assigned CVSS 7.8 and says a remote attacker can execute arbitrary code if a user opens a malicious file or visits a malicious page. The advisory does not report in-the-wild exploitation.
- CVE-2026-91797 is a portfolio directory-traversal flaw in Foxit PDF Reader.
- ZDI rates it CVSS 7.8 with remote code execution impact.
- The user must open a malicious file or visit a malicious page.
- The advisory does not report active exploitation.
Vulnerabilities mentionedAll →
- CVE-2026-917977.8—Path Traversal in Foxit PDF Editor/Reader Vulnerabilitypublished · Foxit PDF Editor/Reader
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-91797 | Path Traversal in Foxit PDF Editor/Reader Vulnerability Foxit PDF Editor/Reader has a vulnerability where it fails to validate the directory traversal path in attached PDF filenames, allowing malicious files to be written to directories outside the expected secure area when the PDF is opened. This flaw is triggered by an attacker who can manipulate the filename to bypass path restrictions. An attacker can therefore gain unauthorized access to sensitive directories and potentially execute arbitrary commands or modify system files. The affected scope is limited to Foxit PDF Editor/Reader, and current public exploitation is not known. Do: Upgrade to patched versions of Foxit PDF Editor/Reader. Implement and enforce strict path validation and sandboxed attachment handling to prevent directory traversal. Regularly audit and scan for exposed PDF attachments and restrict access to secure directories. |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91797.
This source does not provide full text. Read it at zerodayinitiative.com.