CVE-2026-91805: Use-after-free Vulnerability in Foxit PDF Editor/Reader Page-tree Handling
Published Sep 23, 2026
·Updated
A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s PDF page-tree handling. A specially crafted PDF can trigger page-structure changes during rendering, causing the application to access released page objects and resulting in memory corruption and an application crash.
Affected Software
1 affected component
Foxit PDF Editor/Reader
Event History
Sep 23, 2026
CVE Published
via MITRE·07:50 AM
Data Sourced
via MITRE·07:50 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What must an attacker do to exploit this issue?
An attacker must provide a specially crafted PDF and induce the user to interact with it so that the application renders it. The vulnerability has a local attack vector and requires user interaction; no privileges are required.
2
What is the likely impact if exploitation succeeds?
Successful exploitation can cause memory corruption and an application crash. The supplied severity vector indicates potential high impact to confidentiality, integrity, and availability.