CVE-2026-91815 HIGH

CVE-2026-91815: Foxit PDF Editor/Reader JPEG2000 Parsing Memory Corruption Remote Code Execution Vulnerability

Vendor Foxit Software Inc.
Product Foxit PDF Editor
Weakness CWE-787
Published September 23, 2026
Last update September 23, 2026

CVSS base score

7.8/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

Foxit PDF Editor/Reader does not perform sufficient verification of the JPEG2000 image metadata in the PDF file, which leads to out-of-bounds write in the heap buffer during decoding, potentially causing the program to crash and introducing the risk of arbitrary code execution.

Key dates

02Disclosure timeline

September 23, 2026 CVE published