← Back to search

CVE-2026-91798

8.8 HIGH

Published 2026-09-23 · Updated 2026-09-23

AI risk analysis

Summary
The flaw allows regular users to modify the configuration file of Foxit PDF Editor/Reader, leading to potential arbitrary script execution with elevated privileges.
Exploitability
Exploitation is relatively straightforward given the insecure permission configuration, requiring only local access and modification of the configuration file.
Blast radius
If exploited, this vulnerability could result in full system compromise, as arbitrary scripts could be executed with higher privileges.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to the latest version of Foxit PDF Editor/Reader, as no specific version is mentioned in the description.
rceprivilege-escalationconfig-bug

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

A local privilege escalation vulnerability exists in the update daemon of Foxit PDF Editor/Reader due to an insecure permission configuration that allows the configuration file to be modified by regular users, which may lead to arbitrary script execution with higher privileges.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-732

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.