Description
A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of PDF annotations. Reentrant annotation deletion triggered by embedded JavaScript can cause the application to access an annotation object after it has been released, resulting in a use-after-free condition and application crash.
Published: 2026-09-23
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

A use‑after‑free flaw occurs in Foxit PDF Editor and Reader when processing annotations in documents that include embedded JavaScript. The flaw allows the program to access memory after an annotation object has been released, which can trigger a crash or potentially enable remote code execution by executing arbitrary code placed in the corrupted memory area. The vulnerability is classified as CWE‑416.

Affected Systems

The flaw affects Foxit Software Inc.’s PDF Editor and PDF Reader applications. No specific vulnerable version numbers are reported, implying that the issue could exist in current releases used in the field.

Risk and Exploitability

The CVSS score of 7.8 indicates a high severity, while the EPSS score of less than 1% suggests a low likelihood of widespread exploitation at the moment. The vulnerability is not listed in KEV. Attack vectors would involve a malicious PDF file sent to a user; the embedded JavaScript triggers the re‑entrant deletion, creating the use‑after‑free. Since the flaw can lead to arbitrary code execution, this presents a serious risk if attackers can embed malicious PDFs into legitimate workflows.

Generated by OpenCVE AI on September 23, 2026 at 14:56 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Foxit PDF Editor or Reader update that addresses the use‑after‑free issue.
  • Configure Foxit to disable JavaScript execution in PDFs or use minimal‑privilege mode; this reduces the chance that malicious script triggers the flaw.
  • Limit the use of PDF annotations or open suspicious files in a sandboxed environment to isolate the application from the rest of the system.

Generated by OpenCVE AI on September 23, 2026 at 14:56 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 23 Sep 2026 11:45:00 +0000

Type Values Removed Values Added
Description A use-after-free vulnerability exists in Foxit PDF Editor/Reader’s handling of PDF annotations. Reentrant annotation deletion triggered by embedded JavaScript can cause the application to access an annotation object after it has been released, resulting in a use-after-free condition and application crash.
Title Foxit PDF Editor/Reader AcroForm Use-After-Free Remote Code Execution Vulnerability
Weaknesses CWE-416
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Foxit

Published:

Updated: 2026-09-23T14:23:56.070Z

Reserved: 2026-09-15T07:34:45.816Z

Link: CVE-2026-91816

cve-icon Vulnrichment

Updated: 2026-09-23T14:23:02.030Z

cve-icon NVD

Status : Received

Published: 2026-09-23T08:17:13.900

Modified: 2026-09-23T15:17:28.320

Link: CVE-2026-91816

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-23T15:00:06Z

Weaknesses