Skip to main content
Vulnerability Database/CVE-2026-91789

CVE-2026-91789: Foxit PDF Editor/Reader RCE Vulnerability

CVE-2026-91789 is a remote code execution flaw in Foxit PDF Editor/Reader affecting U3D/GIF texture decoding. Attackers can exploit improper image dimension validation to trigger memory corruption. This article covers technical details, affected versions, impact assessment, and mitigation strategies.

Published:

CVE-2026-91789 Overview

Foxit PDF Editor and Foxit PDF Reader contain an out-of-bounds write vulnerability [CWE-787] in the Universal 3D (U3D) and Graphics Interchange Format (GIF) texture decoding path. The affected code performs insufficient validation of image dimensions and related size fields. An attacker can craft a malicious PDF that triggers an incorrectly sized memory allocation followed by an out-of-bounds write during pixel processing. Successful exploitation can lead to arbitrary code execution in the context of the current user. Exploitation requires user interaction, such as opening a crafted document.

Critical Impact

A crafted PDF opened in a vulnerable Foxit build can trigger memory corruption in the texture decoder and lead to remote code execution under the current user's privileges.

Affected Products

  • Foxit PDF Editor (versions listed in the Foxit Security Bulletins)
  • Foxit PDF Reader (versions listed in the Foxit Security Bulletins)
  • Refer to the Foxit Security Bulletins for the exact affected build ranges

Discovery Timeline

  • 2026-09-23 - CVE-2026-91789 published to the National Vulnerability Database
  • 2026-09-23 - Last updated in NVD database

Technical Details for CVE-2026-91789

Vulnerability Analysis

The defect resides in the texture decoding path used when Foxit parses U3D annotations and embedded GIF image resources within a PDF. The parser reads attacker-controlled dimension and size fields from the image stream and uses them to size a destination pixel buffer. Because the parser does not properly validate the relationship between declared dimensions, stride, color depth, and total byte count, the resulting allocation can be smaller than the number of bytes that the pixel loop later writes. The subsequent copy or decode loop then writes past the end of the heap allocation, corrupting adjacent heap metadata or object pointers.

This class of image-decoder flaw is a well-understood path to remote code execution. An attacker who controls the corrupted region can influence virtual table pointers, function callbacks, or object headers used later in the same process, converting the write primitive into control-flow hijack.

Root Cause

The root cause is missing or incorrect bounds arithmetic when computing the pixel buffer size from untrusted image metadata. The decoder trusts fields such as width, height, and per-pixel size without verifying that width * height * bpp fits the allocated buffer and without checking for integer overflow in that multiplication. This is a classic [CWE-787] out-of-bounds write, frequently coupled with an integer overflow in size computation.

Attack Vector

Exploitation requires local user interaction: the victim must open a malicious PDF in a vulnerable Foxit product. Delivery vectors include email attachments, drive-by download of PDF files, and PDF links opened from chat or collaboration tools. No elevated privileges are required, and exploitation results in code execution as the user running Foxit. Because U3D and GIF resources are parsed as part of normal document rendering, no additional interaction beyond opening the file is necessary.

No public proof-of-concept and no in-the-wild exploitation have been reported at the time of publication.

Detection Methods for CVE-2026-91789

Indicators of Compromise

  • PDF files containing malformed U3D annotations or embedded GIF resources with anomalous width, height, or size fields
  • Crashes of FoxitPDFReader.exe or FoxitPDFEditor.exe with access violations in image or texture decoding modules
  • Unexpected child processes spawned by a Foxit process shortly after a PDF is opened

Detection Strategies

  • Hunt for Foxit processes spawning shells, script interpreters, or LOLBins such as powershell.exe, cmd.exe, wscript.exe, or rundll32.exe
  • Alert on Foxit process crashes followed by suspicious file writes, persistence changes, or outbound network connections
  • Inspect inbound PDFs at the mail and web gateway for U3D streams and embedded GIF textures with inconsistent dimension metadata

Monitoring Recommendations

  • Enable Windows Error Reporting collection for Foxit binaries and forward crash telemetry to the SIEM
  • Monitor endpoint EDR telemetry for image-parser exceptions in Foxit modules combined with heap corruption indicators
  • Track Foxit version inventory across managed endpoints to identify hosts still running vulnerable builds

How to Mitigate CVE-2026-91789

Immediate Actions Required

  • Update Foxit PDF Editor and Foxit PDF Reader to the fixed versions listed in the Foxit Security Bulletins
  • Restrict opening of PDFs from untrusted sources until patching is complete
  • Instruct users to report unexpected Foxit crashes triggered by document opening

Patch Information

Foxit has published fixed builds through its security bulletin page. Administrators should consult the Foxit Security Bulletins for the specific patched versions of Foxit PDF Editor and Foxit PDF Reader that address the U3D and GIF texture decoding flaw, then deploy those builds through standard software distribution.

Workarounds

  • Disable 3D content rendering in Foxit preferences to block U3D annotation parsing
  • Enable Foxit Safe Reading Mode to reduce the attack surface exposed by untrusted PDFs
  • Use application allow-listing or attachment filtering to block PDF delivery from external, low-trust senders while patches are staged
bash
# Example: block execution of unpatched Foxit binaries via AppLocker publisher rule
# Replace <VulnerableVersion> with versions listed as affected in the Foxit bulletin
New-AppLockerPolicy -RuleType Publisher `
  -User Everyone `
  -Action Deny `
  -FilePath "C:\Program Files\Foxit Software\Foxit PDF Reader\FoxitPDFReader.exe" `
  -FileVersion "<VulnerableVersion>"

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.