CVE-2026-91788: Foxit Software Inc Foxit PDF Editor

Medium severity, CVSS 4.7. EPSS: 0.1% chance of exploitation in the next 30 days.

When implementing the JavaScript interface, Foxit PDF Editor/Reader did not perform the attribute authorization checks required by the specification. As a result, a trusted malicious PDF could potentially access sensitive content from other documents within the same process and transmit it externally.

Affected products

  • Foxit Software Inc Foxit PDF Editor: up to and including 2026.2; up to and including 14.0.7; up to and including 13.2.6
  • Foxit Software Inc Foxit PDF Reader: up to and including 2026.2

Published 2026-09-23. Last modified 2026-09-23.