CVE-2026-91789: Foxit PDF Editor/Reader U3D File Parsing Integer Overflow Remote Code Execution Vulnerability
Published Sep 23, 2026
·Updated
Foxit PDF Editor/Reader’s U3D/GIF texture decoding path contained insufficient validation of image dimensions and related size information. Under certain conditions, this could lead to an incorrectly sized memory allocation and a subsequent out-of-bounds write during pixel processing, potentially resulting in remote code execution.
Affected Software
1 affected component
Foxit PDF Editor/Reader
Event History
Sep 23, 2026
CVE Published
via MITRE·07:49 AM
Data Sourced
via MITRE·07:49 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What must an attacker do to exploit this issue?
An attacker would need to provide a crafted file that reaches the U3D/GIF texture decoding path. Because user interaction is required, a victim would need to open or otherwise process the malicious content.
2
What is the likely impact if exploitation succeeds?
The out-of-bounds write during pixel processing could potentially allow remote code execution. The supplied severity vector indicates high impacts to confidentiality, integrity, and availability.