CVE-2026-91794 Overview
CVE-2026-91794 is an out-of-bounds write vulnerability [CWE-787] in the PDF rendering process of Foxit PDF Editor and Foxit PDF Reader. The flaw stems from insufficient consistency and boundary validation when parsing malformed color space data inside a PDF document. An attacker can craft a malicious PDF that triggers memory corruption during rendering. Successful exploitation may crash the application and can lead to remote code execution in the context of the current user. Exploitation requires the user to open the crafted document, giving the vector a local attack profile with user interaction.
Critical Impact
A crafted PDF opened in a vulnerable Foxit build can corrupt process memory during color space parsing, enabling arbitrary code execution as the current user.
Affected Products
- Foxit PDF Editor
- Foxit PDF Reader
- Refer to the Foxit Security Bulletins for specific affected versions
Discovery Timeline
- 2026-09-23 - CVE-2026-91794 published to NVD
- 2026-09-23 - Last updated in NVD database
Technical Details for CVE-2026-91794
Vulnerability Analysis
The vulnerability resides in the PDF rendering pipeline that interprets color space objects embedded in a document. When the parser encounters malformed color space data, it fails to enforce consistent bounds between declared and actual component values. The rendering code then writes past the end of an allocated buffer, corrupting adjacent heap memory. This corruption can be shaped by an attacker to overwrite object metadata, function pointers, or virtual table entries used later during rendering.
The issue is classified under [CWE-787] Out-of-Bounds Write. Exploitation requires a user to open a malicious PDF locally, which aligns with the local attack vector and user interaction requirements defined in the advisory. The condition affects confidentiality, integrity, and availability because arbitrary writes in the renderer can be turned into code execution within the application process.
Root Cause
The root cause is missing consistency and boundary checks in the color space processing routine. The parser trusts size or index values derived from the PDF object without validating them against the destination buffer size. A crafted color space definition supplies inconsistent parameters that pass initial checks but produce an out-of-range index during the write operation.
Attack Vector
An attacker delivers a crafted PDF through email attachments, drive-by download pages, chat platforms, or shared storage. When a user opens the document in a vulnerable Foxit PDF Editor or Reader build, the renderer parses the malicious color space object and triggers the out-of-bounds write. No authentication is required, but the target must open the file.
A proof-of-concept has not been published, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. The EPSS forecast currently reports a low probability of near-term exploitation. Refer to the Foxit Security Bulletins for technical details on the color space parsing routine.
Detection Methods for CVE-2026-91794
Indicators of Compromise
- Unexpected crashes of FoxitPDFReader.exe or FoxitPDFEditor.exe shortly after opening a PDF, particularly with access-violation exceptions in rendering modules.
- PDF files containing unusual or malformed color space entries such as /ColorSpace, /DeviceN, /ICCBased, or /Indexed with inconsistent component counts.
- Foxit processes spawning unexpected child processes such as cmd.exe, powershell.exe, or rundll32.exe.
- Outbound network connections initiated by Foxit processes to unfamiliar hosts following the opening of an untrusted PDF.
Detection Strategies
- Deploy behavioral endpoint detection rules that flag Foxit processes launching scripting interpreters or writing executables to disk.
- Enable Windows Error Reporting and forward crash telemetry from Foxit binaries to a central log store for triage.
- Use YARA rules that inspect PDF color space dictionaries for structural anomalies and oversized component arrays.
- Correlate PDF open events with subsequent process creation and network events to surface exploitation chains.
Monitoring Recommendations
- Monitor process creation events (Sysmon Event ID 1) where the parent image is a Foxit binary.
- Track file writes by Foxit processes to user-writable locations such as %APPDATA%, %TEMP%, and %PUBLIC%.
- Alert on module loads of unsigned DLLs into Foxit processes.
- Aggregate crash telemetry across the fleet to identify clustering that may indicate targeted exploitation.
How to Mitigate CVE-2026-91794
Immediate Actions Required
- Apply the latest security update for Foxit PDF Editor and Foxit PDF Reader as published in the Foxit Security Bulletins.
- Inventory endpoints running Foxit products and prioritize patching for users who routinely open PDFs from external sources.
- Instruct users to avoid opening PDF attachments from untrusted senders until patches are deployed.
- Restrict Foxit process privileges and enforce standard user contexts to limit the impact of successful exploitation.
Patch Information
Foxit publishes fixed versions in its security bulletins. Administrators should consult the Foxit Security Bulletins page to identify the specific patched build for their product line and deploy it through their standard software update process.
Workarounds
- Configure the operating system to open PDFs in a hardened viewer or sandboxed browser until Foxit updates are applied.
- Disable PDF preview in email clients and file explorers to prevent automatic rendering of untrusted documents.
- Enforce attachment filtering at the email gateway to quarantine PDFs from unknown external senders.
- Apply application control policies that restrict Foxit processes from spawning shells or scripting hosts.
# Example: block Foxit processes from launching common LOLBins via Windows Defender Application Control or AppLocker
# AppLocker rule (PowerShell) - deny PowerShell and cmd when parent is Foxit
New-AppLockerPolicy -RuleType Path -User Everyone -Action Deny \
-Path "%SYSTEMROOT%\System32\WindowsPowerShell\v1.0\powershell.exe" \
-Description "Deny PowerShell execution spawned from Foxit"
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
