CVE-2026-91798: Foxit PDF Editor/Reader Updater Privilege Escalation
A local privilege escalation vulnerability exists in the update daemon of Foxit PDF Editor/Reader due to an insecure permission configuration that allows the configuration file to be modified by regular users, which may lead to arbitrary script execution with higher privileges.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to this issue?
Systems running Foxit PDF Editor or Reader with the affected update daemon are exposed if regular users can modify its configuration file. The issue is local, so it applies to users who can log on to or otherwise execute code on the system.
What does an attacker need to exploit it?
An attacker needs local access with regular-user privileges and the ability to modify the update daemon configuration file. No user interaction is required once those conditions are met.
What is the likely impact of successful exploitation?
A successful attacker may cause arbitrary scripts to execute with higher privileges. This can affect confidentiality, integrity, and availability of the affected system.
What can be done if patching is not immediately possible?
Restrict modification of the update daemon configuration file so regular users cannot write to it. Review its permissions and remove inappropriate write access until an update is available.