CVE-2026-91801: Foxit PDF Editor/Reader RichMedia Annotation Directory Traversal Remote Code Execution Vulnerability
A path traversal vulnerability exists in Foxit PDF Editor/Reader's handling of embedded PDF resources. Insufficient validation of resource file paths may allow files to be written outside their intended locations, potentially enabling arbitrary code execution.
Affected Software
Event History
Frequently Asked Questions
What must an attacker do to exploit this issue?
An attacker would need to convince a user to interact with a malicious PDF containing embedded resources with crafted file paths. The CVSS vector indicates user interaction is required, while no attacker privileges are required.
Is exploitation remote or does it require local access?
The CVSS vector lists local attack vector (AV:L). However, the described attack involves a malicious PDF and requires user interaction; the provided information does not further explain the delivery mechanism or local-access requirement.
What is the potential impact if exploitation succeeds?
A successful exploit may write files outside intended locations and potentially lead to arbitrary code execution. The supplied CVSS metrics rate confidentiality, integrity, and availability impact as high.