Skip to main content
Vulnerability Database/CVE-2026-91807

CVE-2026-91807: Foxit PDF Editor Buffer Overflow Vulnerability

CVE-2026-91807 is a heap-based buffer overflow in Foxit PDF Editor/Reader affecting image soft-mask parsing. Attackers can trigger application crashes through malformed PDFs. This article covers technical details, impact assessment, and mitigation strategies.

Published:

CVE-2026-91807 Overview

CVE-2026-91807 is a heap-based out-of-bounds read vulnerability in Foxit PDF Editor and Foxit PDF Reader. The flaw resides in the image parsing logic that processes soft-mask data attributes. Insufficient validation of the soft-mask attribute allows an arithmetic underflow during parsing. The underflow produces an invalid length or offset, which the reader subsequently uses to read past the bounds of a heap buffer. Successful triggering results in an application crash and may expose adjacent heap memory contents. The issue is tracked under CWE-125: Out-of-bounds Read and requires a user to open a crafted PDF locally.

Critical Impact

A malicious PDF can crash Foxit PDF Editor/Reader and potentially disclose heap memory adjacent to the image buffer.

Affected Products

  • Foxit PDF Editor (see vendor bulletins for exact versions)
  • Foxit PDF Reader (see vendor bulletins for exact versions)
  • Refer to Foxit Security Bulletins for the authoritative version list

Discovery Timeline

  • 2026-09-23 - CVE CVE-2026-91807 published to NVD
  • 2026-09-23 - Last updated in NVD database

Technical Details for CVE-2026-91807

Vulnerability Analysis

The vulnerability occurs in the code path that parses image objects containing a soft-mask (SMask) entry inside a PDF. Foxit's parser reads attributes describing the soft-mask dimensions or stream length without adequately validating the values against expected bounds. A crafted attribute value triggers an arithmetic underflow when the parser computes an offset or size for the pixel data buffer. The resulting value wraps to a large unsigned integer or a negative index depending on the intermediate type. The parser then dereferences that computed pointer, reading memory beyond the allocated heap region. Because triggering requires opening a document (UI:R) and executes with local scope (AV:L), the attacker's delivery channel is typically a phishing email or a lure hosted on the web. The primary observable outcome is process termination, though the disclosed adjacent memory may aid subsequent exploitation attempts against paired vulnerabilities.

Root Cause

The root cause is missing bounds validation on the soft-mask data attribute before it participates in pointer or length arithmetic. When the attribute value is smaller than a subtracted constant, the computation underflows and yields an invalid buffer size or index that bypasses subsequent sanity checks.

Attack Vector

An attacker crafts a PDF containing an image object with a malformed soft-mask attribute and delivers it to the target. The victim opens the file in Foxit PDF Editor or Reader, causing the parser to perform the flawed arithmetic and read out of bounds. No authentication is required, and the attack executes in the security context of the local user.

No public proof-of-concept code is available for CVE-2026-91807 at the time of publication. See the Foxit Security Bulletins for vendor-supplied technical details.

Detection Methods for CVE-2026-91807

Indicators of Compromise

  • Unexpected crashes of FoxitPDFReader.exe or FoxitPDFEditor.exe shortly after opening a PDF from email or the web
  • Windows Error Reporting entries referencing access violations in Foxit image-parsing modules
  • PDF documents from untrusted senders containing image objects with malformed SMask entries

Detection Strategies

  • Hunt for process crash telemetry where the faulting module belongs to a Foxit installation and the parent activity involves opening an attachment
  • Inspect email gateways and web proxies for PDFs with anomalous image dictionaries, particularly unusual SMask length or dimension values
  • Correlate Foxit process termination events with recent file-open activity to surface repeated crash patterns across endpoints

Monitoring Recommendations

  • Enable application crash logging and forward Foxit-related events to a central SIEM for correlation
  • Track versions of Foxit PDF Editor and Reader deployed across the fleet to identify unpatched hosts
  • Alert on PDF files that trigger multiple parser exceptions within a short interval on the same endpoint

How to Mitigate CVE-2026-91807

Immediate Actions Required

  • Inventory endpoints running Foxit PDF Editor and Foxit PDF Reader and identify versions below the fixed release listed in the vendor bulletin
  • Apply the vendor-supplied update as soon as it is available for your platform
  • Instruct users to avoid opening PDF attachments from untrusted or unexpected senders until patching is complete

Patch Information

Foxit publishes fixed versions and detailed advisory information on the Foxit Security Bulletins page. Consult that page for the specific product build that remediates CVE-2026-91807 and follow the vendor's upgrade instructions.

Workarounds

  • Configure email and web gateways to sandbox or detonate PDF attachments before delivery
  • Restrict Foxit PDF Editor/Reader from being the default handler on high-risk endpoints until the patch is deployed
  • Enable operating system exploit mitigations such as Data Execution Prevention and Address Space Layout Randomization for the Foxit processes
bash
# Example: query installed Foxit versions on Windows endpoints
Get-ItemProperty HKLM:\Software\Microsoft\Windows\CurrentVersion\Uninstall\* |
  Where-Object { $_.DisplayName -like 'Foxit*' } |
  Select-Object DisplayName, DisplayVersion, InstallLocation

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.