CVE-2026-91813 HIGH

CVE-2026-91813: Foxit PDF Editor/Reader FoxitUpdater Race Condition Local Privilege Escalation Vulnerability

Vendor Foxit Software Inc.
Product Foxit PDF Editor
Weakness CWE-367
Published September 23, 2026
Last update September 23, 2026

CVSS base score

8.8/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

What the vulnerability does

01Description

A vulnerability in Foxit PDF Editor/Reader’s update mechanism allows an update package to be replaced between download and high-privilege extraction due to insufficient file locking and integrity validation. This could enable local attackers to execute arbitrary code with elevated privileges.

Key dates

02Disclosure timeline

September 23, 2026 CVE published