← Back to search

CVE-2026-91800

8.8 HIGH

Published 2026-09-23 · Updated 2026-09-23

AI risk analysis

Summary
A local privilege escalation vulnerability in Foxit PDF Editor for macOS allows a local attacker to execute arbitrary commands with root privileges by exploiting insufficient validation of a user-modifiable configuration value during high-privilege upgrades.
Exploitability
Exploitation requires local access and knowledge of the upgrade process, making it moderately difficult.
Blast radius
If exploited, the attacker could gain full control over the affected system, leading to potential data loss, system compromise, and further attacks.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Upgrade to the latest version of Foxit PDF Editor for macOS as soon as possible.
rceprivilege-escalationmacospdf

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

A local privilege escalation vulnerability exists in the installer of Foxit PDF Editor for macOS due to insufficient validation of a user-modifiable configuration value during high-privilege upgrades. A local attacker could exploit this issue to execute arbitrary commands with root privileges.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-732

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.