CVE-2026-91810: Foxit PDF Editor/Reader Doc Object Out-Of-Bounds Read Information Disclosure Vulnerability
Published Sep 23, 2026
·Updated
A heap-based out-of-bounds read vulnerability exists in Foxit PDF Editor/Reader’s handling of malformed PDF image masks. Inconsistent image metadata may cause incorrect alpha-channel processing during rendering, resulting in an out-of-bounds read and application crash.
Affected Software
1 affected component
Foxit PDF Editor/Reader
Event History
Sep 23, 2026
CVE Published
via MITRE·07:50 AM
Data Sourced
via MITRE·07:50 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What interaction is required for exploitation?
The attack requires user interaction, such as opening or rendering a malicious PDF in the affected application. No privileges are required by the attacker.
2
What is the expected impact if exploitation succeeds?
The vulnerability can disclose information through an out-of-bounds read and can cause the application to crash. The reported impact includes low confidentiality impact and high availability impact.