CVE-2026-91806: Foxit PDF Editor/Reader Doc Object Use-After-Free Information Disclosure Vulnerability
Published Sep 23, 2026
·Updated
A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of PDF form fields. Embedded JavaScript may access form-field references after the corresponding fields have been released, resulting in an application crash.
Affected Software
1 affected component
Foxit PDF Editor/Reader
Event History
Sep 23, 2026
CVE Published
via MITRE·07:50 AM
Data Sourced
via MITRE·07:50 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What must an attacker provide to trigger this issue?
The issue is triggered through a PDF containing form fields and embedded JavaScript. User interaction is required, and exploitation is local according to the supplied vector.
2
What is the confirmed impact?
The provided description confirms that accessing released form-field references can crash Foxit PDF Editor or Reader. The severity vector also rates confidentiality, integrity, and availability impact as high.