CVE-2026-91798

8.8

Foxit · Foxit PDF Editor and Foxit PDF Reader

An insecure configuration in the Foxit PDF update daemon allows local users to modify files, potentially leading to arbitrary script execution with elevated privileges.

Executive summary

An insecure permission vulnerability in the Foxit PDF update daemon allows local low-privileged users to escalate their privileges to arbitrary levels, posing a severe risk of system compromise.

Vulnerability

This is a local privilege escalation flaw (CWE-732) occurring within the update daemon. An attacker with low-level local access can exploit insecure permission settings to modify configuration files, resulting in arbitrary code execution with administrative or system-level privileges.

Business impact

The vulnerability carries a CVSS score of 8.8, reflecting its potential for a complete compromise of the affected host. Successful exploitation enables a malicious actor to bypass standard user restrictions, potentially resulting in data exfiltration, the installation of persistent backdoors, or full system takeover.

Remediation

Immediate Action: Monitor official Foxit security bulletins for the release of a patched version and apply the update to all endpoints immediately upon availability.

Proactive Monitoring: Review system logs for unauthorized modifications to update daemon configuration files or unexpected process execution patterns originating from the Foxit update service.

Compensating Controls: Restrict local user write access to the directory path associated with the Foxit update daemon configuration to prevent unauthorized modifications until a formal patch can be deployed.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the high severity of this local privilege escalation vulnerability, organizations should treat this as a significant security risk. Security teams must prioritize patching as soon as the vendor provides a fix, while simultaneously enforcing strict least-privilege policies on workstations to limit the potential for local attackers to leverage such flaws.

More Foxit CVEs all →

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief high section

Sources

Originally found and disclosed by Dominic Musgrave, per the CVE Program record.