CVE-2026-91809: Foxit PDF Editor/Reader Annotation Use-After-Free Information Disclosure Vulnerability
Published Sep 23, 2026
·Updated
A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of malformed PDF form fields. Improper validation during field-name traversal may cause the application to access a released object, resulting in an application crash.
Affected Software
1 affected component
Foxit PDF Editor/Reader
Event History
Sep 23, 2026
CVE Published
via MITRE·07:49 AM
Data Sourced
via MITRE·07:49 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What would an attacker need to do to trigger the issue?
The attacker would need to provide a PDF containing malformed form fields and rely on user interaction with the file. The vulnerability is triggered during field-name traversal.
2
Does exploitation require attacker privileges?
No privileges are required according to the supplied vector. The attack vector is local, so the vulnerable application must process the malicious PDF on the affected system.