Time-of-check Time-of-use (TOCTOU) Race Condition in Foxit PDF Editor (formerly Foxit PhantomPDF) and Foxit PDF Reader for Windows - CVE-2026-91813
Published: September 23, 2026
Vulnerability identifier: #VU151834
CSH Severity: Low
CVSS v4: 8.5 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-91813
CWE-ID: CWE-367
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to a time-of-check time-of-use race condition in the update process when downloading and extracting update files. A local user can race update file operations to escalate privileges.
Affected software
Foxit PDF Editor (formerly Foxit PhantomPDF)
Foxit PDF Reader for Windows
Foxit PDF Reader for Windows
How to mitigate CVE-2026-91813
Install security update from vendor's website.
Foxit PDF Editor (formerly Foxit PhantomPDF) - addressed in versions 13.2.7.24160, 14.0.8.33807, 2026.2.1.39815
Foxit PDF Reader for Windows - update to 2026.2.1.39815
Foxit PDF Reader for Windows - update to 2026.2.1.39815