CVE-2026-91794: Foxit PDF Editor/Reader DeviceN Colorspace Out-Of-Bounds Write Remote Code Execution Vulnerability
Published Sep 23, 2026
·Updated
An out-of-bounds write vulnerability exists in the PDF rendering process of Foxit PDF Editor/Reader due to insufficient consistency and boundary validation when processing malformed color space data, which may cause the program to crash and potentially lead to remote code execution.
Affected Software
1 affected component
Foxit PDF Editor/Reader
Event History
Sep 23, 2026
CVE Published
via MITRE·07:51 AM
Data Sourced
via MITRE·07:51 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What does an attacker need to do to exploit this vulnerability?
An attacker would need to convince a user to open or render a malicious PDF containing malformed DeviceN color space data. The CVSS vector indicates local attack vector, no privileges required, and user interaction required.
2
What is the potential impact if exploitation succeeds?
The malformed PDF can cause Foxit PDF Editor/Reader to crash and may allow remote code execution. The listed severity vector rates confidentiality, integrity, and availability impact as high.