ZDI-26-735: Foxit PDF Reader Doc Object Use-After-Free Information Disclosure Vulnerability
ZDI reported a Foxit PDF Reader Doc object use-after-free that can leak information after user interaction (CVE-2026-91806).
ZDI-26-735 describes a use-after-free in Foxit PDF Reader's Doc object handling that can let a remote attacker disclose sensitive information. The target must open a malicious file or visit a malicious page. ZDI assigned CVSS 3.3 and CVE-2026-91806, and does not claim exploitation in the wild.
- Doc object use-after-free can disclose sensitive information.
- User must open a malicious file or visit a malicious page.
- ZDI rates it CVSS 3.3; CVE-2026-91806 is assigned.
- No active exploitation is reported.
Vulnerabilities mentionedAll →
- CVE-2026-918067.8—Unauthenticated Use-After-Free in Foxit PDF Editor/Reader 5.0+ (CVE-2026-91806)published · Foxit PDF Editor/Reader
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-91806 | Unauthenticated Use-After-Free in Foxit PDF Editor/Reader 5.0+ (CVE-2026-91806) This vulnerability involves a use-after-free flaw in Foxit PDF Editor/Reader that allows embedded JavaScript to access form-field references after the fields are released, potentially causing application crashes. An attacker can exploit this by exploiting the unvalidated form-field references, gaining unauthorized access to sensitive system data or other application functionality. The affected scope includes Foxit PDF Editor/Reader across all known versions, though specific version ranges are not provided in the data. Current exploitation status is none_known, with no public PoC available. Do: Upgrade to patched versions of Foxit PDF Editor/Reader. Apply mitigations such as form-field lifecycle validation and input sanitization. Monitor affected products for deployment and verify compliance. |
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-91806.
This source does not provide full text. Read it at zerodayinitiative.com.