CVE-2026-91793: Foxit PDF Editor/Reader Doc Object Use-After-Free Information Disclosure Vulnerability
Published Sep 23, 2026
·Updated
When opening a specially crafted PDF, Foxit PDF Editor/Reader executes scripts that modify annotation rich-text attributes containing malformed font data. During subsequent annotation appearance reconstruction, it accesses an object after it has been released, resulting in a use-after-free condition and an application crash.
Affected Software
1 affected component
Foxit PDF Editor/Reader
Event History
Sep 23, 2026
CVE Published
via MITRE·07:51 AM
Data Sourced
via MITRE·07:51 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What must an attacker do to trigger this issue?
The attacker must persuade a user to open a specially crafted PDF. The PDF uses scripts to modify annotation rich-text attributes with malformed font data.
2
What is the observed impact after the malicious PDF is opened?
During annotation appearance reconstruction, the application accesses an object after it has been released. The described result is a use-after-free condition and an application crash.