External Control of File Name or Path in Foxit PDF Editor (formerly Foxit PhantomPDF) and Foxit PDF Reader for Windows - CVE-2026-91797

 

External Control of File Name or Path in Foxit PDF Editor (formerly Foxit PhantomPDF) and Foxit PDF Reader for Windows - CVE-2026-91797

Published: September 23, 2026


Vulnerability identifier: #VU151830
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-91797
CWE-ID: CWE-73
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary code.

The vulnerability exists due to external control of file name or path in PDF portfolio attachment handling when processing embedded malicious file paths. A remote attacker can trick the victim into opening a crafted PDF portfolio to execute arbitrary code.

The application directly uses attachment filenames referenced by Filespec entries.


Affected software

Foxit PDF Editor (formerly Foxit PhantomPDF)
Foxit PDF Reader for Windows

How to mitigate CVE-2026-91797

Install security update from vendor's website.

Foxit PDF Editor (formerly Foxit PhantomPDF) - addressed in versions 13.2.7.24160, 14.0.8.33807, 2026.2.1.39815
Foxit PDF Reader for Windows - update to 2026.2.1.39815

External References

Related Security Bulletins