CVE-2026-91813
8.8Foxit Software · Foxit PDF Editor and Reader
A race condition in the Foxit PDF update mechanism allows local attackers to replace update packages before extraction, potentially leading to arbitrary code execution with elevated privileges.
Executive summary
A critical race condition in the Foxit PDF update process could allow a local attacker to achieve arbitrary code execution with elevated system privileges.
Vulnerability
The software suffers from a Time of check Time of use (TOCTOU) race condition within its update mechanism. A local attacker with low privileges can exploit the lack of file locking and integrity validation to substitute legitimate update packages with malicious payloads during the download process.
Business impact
Successful exploitation allows an attacker to gain full control over the affected system by executing code with elevated privileges. Given the CVSS score of 8.8, this vulnerability poses a significant risk to organizational integrity, as it facilitates complete system compromise, potential data exfiltration, and the deployment of persistent threats within the environment.
Remediation
Immediate Action: Review the official Foxit Security Bulletins at https://www.foxit.com/support/security-bulletins.html and apply the vendor provided security updates as soon as they are released for your specific version.
Proactive Monitoring: Monitor local system logs for unusual process creation events or unauthorized file modifications in directories associated with the Foxit update service.
Compensating Controls: Restrict local user permissions where possible to limit the ability of unauthorized users to modify files in system directories, effectively narrowing the attack surface for local TOCTOU exploits.
Exploitation status
Public Exploit Available: No — exploit_available (false).
Analyst recommendation
This vulnerability represents a high-severity risk due to the potential for privilege escalation and arbitrary code execution. Security teams should prioritize monitoring the vendor advisory page and ensure that all Foxit PDF deployments are patched immediately upon the release of the official fix to prevent local attackers from leveraging this race condition.
More Foxit Software CVEs all →
History
- Disclosed CVE record published
- Collected by CVE Brief via github
- Analyst report written
- Published in the daily brief high section
Sources
Originally found and disclosed by praydog & kmx00 working with TrendAI Zero Day Initiative, per the CVE Program record.