ZDI-26-734: Foxit PDF Reader RichMedia Annotation Directory Traversal Remote Code Execution Vulnerability
Foxit PDF Reader RichMedia directory traversal can allow remote code execution after user interaction.
ZDI published advisory ZDI-26-734 for a directory traversal flaw in Foxit PDF Reader's RichMedia annotation handling. Remote attackers can execute arbitrary code if a user opens a malicious file or visits a malicious page. ZDI assigned CVSS 7.8 and CVE-2026-91801. The advisory does not report active exploitation.
- ZDI-26-734 covers a RichMedia annotation directory traversal in Foxit PDF Reader.
- Successful exploitation can lead to remote code execution.
- The target must open a malicious file or visit a malicious page.
- ZDI rated the issue CVSS 7.8; CVE-2026-91801 is assigned.
Vulnerabilities mentionedAll →
- CVE-2026-918017.8—Path Traversal RCE in Foxit PDF Editor/Readerpublished · Foxit PDF Editor/Reader
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-91801 | Path Traversal RCE in Foxit PDF Editor/Reader A path traversal vulnerability in Foxit PDF Editor/Reader exists due to insufficient validation of embedded PDF resource file paths. This flaw allows files to be written outside their intended locations, potentially enabling arbitrary code execution. An attacker could gain full system control by exploiting the vulnerability. The affected products are Foxit PDF Editor/Reader, and the current exploitation status is unknown. Do: Upgrade to the latest version of Foxit PDF Editor/Reader to mitigate the path traversal vulnerability. Implement strict path validation and restrict resource file access to prevent arbitrary code execution. Regularly scan for known CVEs to detect and address security gaps. |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-91801.
This source does not provide full text. Read it at zerodayinitiative.com.