OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-91798

HIGH · CVSS 8.8 EPSS 0.10%

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

A local privilege escalation vulnerability in the update daemon of Foxit PDF Editor/Reader allows regular users to modify the configuration file due to insecure permissions, potentially leading to arbitrary script execution with elevated privileges. Organizations using this software should prioritize patching to mitigate the risk of exploitation, as the high severity rating indicates significant potential for impact.

CVE
CVE-2026-91798
Severity
HIGH
CVSS
8.8
EPSS
0.10%

Original NVD Description

A local privilege escalation vulnerability exists in the update daemon of Foxit PDF Editor/Reader due to an insecure permission configuration that allows the configuration file to be modified by regular users, which may lead to arbitrary script execution with higher privileges.