CVE-2026-91813: Foxit PDF Editor/Reader FoxitUpdater Race Condition Local Privilege Escalation Vulnerability
Published Sep 23, 2026
·Updated
A vulnerability in Foxit PDF Editor/Reader’s update mechanism allows an update package to be replaced between download and high-privilege extraction due to insufficient file locking and integrity validation. This could enable local attackers to execute arbitrary code with elevated privileges.
Affected Software
2 affected components
Foxit Foxit PDF Editor/Reader
Foxit FoxitUpdater
Event History
Sep 23, 2026
CVE Published
via MITRE·07:49 AM
Data Sourced
via MITRE·07:49 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·08:17 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require user interaction?
No. The vulnerability is rated UI:N, indicating that user interaction is not required.
2
What access does an attacker need to exploit this issue?
The attack vector is local (AV:L) and requires low privileges (PR:L). An attacker would need local access and an existing low-privileged account or execution context.