CVE-2026-91798
8.8 HIGHPublished 2026-09-23 · Updated 2026-09-23
AI risk analysis
- Summary
- The flaw allows regular users to modify the configuration file of Foxit PDF Editor/Reader, leading to potential arbitrary script execution with elevated privileges.
- Exploitability
- Exploitation is relatively straightforward given the insecure permission configuration, requiring only local access and modification of the configuration file.
- Blast radius
- If exploited, this vulnerability could result in full system compromise, as arbitrary scripts could be executed with higher privileges.
- Detection
- No reliable host or network indicator is derivable from the published description.
- Prioritized remediation
- Upgrade to the latest version of Foxit PDF Editor/Reader, as no specific version is mentioned in the description.
rceprivilege-escalationconfig-bug
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
A local privilege escalation vulnerability exists in the update daemon of Foxit PDF Editor/Reader due to an insecure permission configuration that allows the configuration file to be modified by regular users, which may lead to arbitrary script execution with higher privileges.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Weaknesses
CWE-732
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.
Related CVEs
- HIGHCVE-2026-91800
- CRITICALCVE-2026-0163
- HIGHCVE-2026-100580PoC
- CRITICALCVE-2026-10090
- HIGHCVE-2026-17052PoC
- CRITICALCVE-2026-24254PoC
- CRITICALCVE-2026-82443
- CRITICALCVE-2026-84474
Related by shared AI tags and CWE weakness class. Browse the full archive.