8.8
CVE-2026-91798
- EPSS 0.1%
- Veröffentlicht 23.09.2026 07:50:17
- Zuletzt bearbeitet 23.09.2026 17:58:26
- Erkennungen
Foxit PDF Editor/Reader Updater Privilege Escalation
A local privilege escalation vulnerability exists in the update daemon of Foxit PDF Editor/Reader due to an insecure permission configuration that allows the configuration file to be modified by regular users, which may lead to arbitrary script execution with higher privileges.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerFoxit Software Inc.
≫
Produkt
Foxit PDF Editor
Default Statusunaffected
Version
Versions 2026.2 and earlier
Status
affected
Version
Versions 14.0.7 and earlier
Status
affected
Version
Versions 13.2.6 and earlier
Status
affected
HerstellerFoxit Software Inc.
≫
Produkt
Foxit PDF Reader
Default Statusunaffected
Version
Versions 2026.2 and earlier
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.1% | 0.009 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 14984358-7092-470d-8f34-ade47a7658a2 | 8.8 | 2 | 6 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
|
CWE-732 Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
https://www.foxit.com/support/security-bulletins.html