MajorCritical vulnerability
CVE-2026-91798 (CVSS 8.8)
NVD · officialPublished Sep 23, 2026Risk 37/100EPSS 0.1%
A local privilege escalation vulnerability exists in the update daemon of Foxit PDF Editor/Reader due to an insecure permission configuration that allows the configuration file to be modified by regular users, which may lead to arbitrary script execution with higher privileges.
Technical details
CVSS
8.8
AV:LocalAC:LowPR:LowUI:NoneC:HighI:HighA:High
Evidence and sources
This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.
Open primary source