CVE-2026-91798: Foxit PDF Editor/Reader Updater Privilege Escalation

Published Sep 23, 2026
·
Updated

A local privilege escalation vulnerability exists in the update daemon of Foxit PDF Editor/Reader due to an insecure permission configuration that allows the configuration file to be modified by regular users, which may lead to arbitrary script execution with higher privileges.

Affected Software

1 affected component
Foxit PDF Editor/Reader Updater

Event History

Sep 23, 2026
CVE Published
via MITRE·07:50 AM
Data Sourced
via MITRE·07:50 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Systems running Foxit PDF Editor or Reader with the affected update daemon are exposed if regular users can modify its configuration file. The issue is local, so it applies to users who can log on to or otherwise execute code on the system.

2

What does an attacker need to exploit it?

An attacker needs local access with regular-user privileges and the ability to modify the update daemon configuration file. No user interaction is required once those conditions are met.

3

What is the likely impact of successful exploitation?

A successful attacker may cause arbitrary scripts to execute with higher privileges. This can affect confidentiality, integrity, and availability of the affected system.

4

What can be done if patching is not immediately possible?

Restrict modification of the update daemon configuration file so regular users cannot write to it. Review its permissions and remove inappropriate write access until an update is available.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203