OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-91797

HIGH · CVSS 7.8 EPSS 0.21%

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

Foxit PDF Editor/Reader is vulnerable due to improper validation of directory traversal paths in attachment file names, allowing attackers to write malicious attachments to unauthorized directories upon opening a PDF. This flaw poses a significant risk of unauthorized file access and potential system compromise. Organizations using this software should prioritize patching to mitigate the risk of exploitation.

CVE
CVE-2026-91797
Severity
HIGH
CVSS
7.8
EPSS
0.21%

Original NVD Description

Foxit PDF Editor/Reader failed to validate the directory traversal path in the attachment file name, resulting in malicious attachments being able to be written to directories outside the expected secure area when the PDF is opened.

Related CVEs

Other vulnerabilities affecting the same vendor(s)