{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-91797", "assignerOrgId": "14984358-7092-470d-8f34-ade47a7658a2", "state": "PUBLISHED", "assignerShortName": "Foxit", "dateReserved": "2026-09-15T07:34:40.287Z", "datePublished": "2026-09-23T07:50:59.659Z", "dateUpdated": "2026-09-23T15:25:48.290Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "14984358-7092-470d-8f34-ade47a7658a2", "shortName": "Foxit", "dateUpdated": "2026-09-23T07:50:59.659Z" }, "title": "Foxit PDF Editor/Reader Portfolio Directory Traversal Remote Code Execution Vulnerability", "problemTypes": [ { "descriptions": [ { "lang": "en", "cweId": "CWE-73", "description": "CWE-73 External control of file name or path", "type": "CWE" } ] } ], "impacts": [ { "descriptions": [ { "lang": "en", "value": "Potential arbitrary code execution" } ] } ], "affected": [ { "vendor": "Foxit Software Inc.", "product": "Foxit PDF Editor", "platforms": [ "Windows" ], "versions": [ { "status": "affected", "version": "Versions 2026.2 and earlier" }, { "status": "affected", "version": "Versions 14.0.7 and earlier" }, { "status": "affected", "version": "Versions 13.2.6 and earlier" } ], "defaultStatus": "unaffected" }, { "vendor": "Foxit Software Inc.", "product": "Foxit PDF Reader", "platforms": [ "Windows" ], "versions": [ { "status": "affected", "version": "Versions 2026.2 and earlier" } ], "defaultStatus": "unaffected" } ], "descriptions": [ { "lang": "en", "value": "Foxit PDF Editor/Reader failed to validate the directory traversal path in the attachment file name, resulting in malicious attachments being able to be written to directories outside the expected secure area when the PDF is opened.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "Foxit PDF Editor/Reader failed to validate the directory traversal path in the attachment file name, resulting in malicious attachments being able to be written to directories outside the expected secure area when the PDF is opened." } ] } ], "references": [ { "url": "https://www.foxit.com/support/security-bulletins.html" } ], "metrics": [ { "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ], "cvssV3_1": { "version": "3.1", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH", "baseSeverity": "HIGH", "baseScore": 7.8, "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" } } ], "credits": [ { "lang": "en", "value": "Landon Peng (lunbun) of Lunbun LLC working with TrendAI Zero Day Initiative", "type": "finder" } ], "x_generator": { "engine": "Vulnogram 1.0.5" } }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-09-23T15:25:36.693438Z", "id": "CVE-2026-91797", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "total" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-09-23T15:25:48.290Z" } } ] } }