← Back to search

CVE-2026-91813

8.8 HIGH

Published 2026-09-23 · Updated 2026-09-23

AI risk analysis

Summary
A vulnerability in Foxit PDF Editor/Reader’s update mechanism allows local attackers to replace an update package, leading to potential execution of arbitrary code with elevated privileges.
Exploitability
Exploitation requires local access and the ability to replace the update package between download and extraction. Precondition is the presence of a local attacker with sufficient privileges.
Blast radius
If exploited, this could result in unauthorized code execution with elevated privileges, potentially leading to full system compromise.
Detection
No reliable host or network indicator is derivable from the published description.
Prioritized remediation
Disable the automatic update feature or ensure that all update packages are validated and verified before extraction.
rcelocal-privilege-escalationfile-integrityupdate-mechanism

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

A vulnerability in Foxit PDF Editor/Reader’s update mechanism allows an update package to be replaced between download and high-privilege extraction due to insufficient file locking and integrity validation. This could enable local attackers to execute arbitrary code with elevated privileges.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

Weaknesses

CWE-367

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.