Home › Intelligence › Brief
VULNERABILITY BRIEF🟡 Medium Vulnerability

Information Disclosure in Foxit PDF Reader (CVE‑2026‑91788) Enables Sensitive Document Exposure

A missing‑authorization bug in Foxit PDF Reader’s JavaScript API can let a remote attacker read other open documents after a user opens a malicious PDF. The flaw scores 4.7 on CVSS and has been patched by Foxit. Organizations must verify authorization controls and maintain patch evidence for audit readiness.

LiveThreat™ Intelligence · 📅 September 26, 2026· 📰 zerodayinitiative.com
🟡
Severity
Medium
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
4 recommended
📰
Source
zerodayinitiative.com

Information Disclosure in Foxit PDF Reader (CVE‑2026‑91788) Enables Sensitive Document Exposure

What It Is – A missing‑authorization flaw in the JavaScript API of Foxit PDF Reader allows a remote attacker, who convinces a user to open a malicious PDF or visit a crafted web page, to read the contents of other documents that the user has open.

Exploitability – Requires user interaction (malicious file or page). No public exploit code is known, and the CVSS v3.1 base score is 4.7 (moderate).

Affected Products – Foxit PDF Reader (all versions prior to the September 2026 security update).

Why It Matters for Trust & Control Assurance

  • Demonstrates the need for authorization enforcement controls that verify a user’s right to access any application‑level function.
  • Highlights the importance of continuous patch monitoring as evidence of due‑diligence for auditors.
  • Shows that application‑level logging of JavaScript API calls can provide a defensible audit trail when a breach investigation is required.

Recommended Actions

  • Deploy Foxit’s September 2026 security update immediately.
  • Review and harden the JavaScript API usage policy on all PDF‑handling workstations.
  • Enable detailed logging of PDF‑related events and integrate logs into your SIEM for continuous monitoring.
  • Validate that your access‑control matrix includes “document‑view” permissions for PDF applications.

Source: Zero Day Initiative advisory ZDI‑26‑720

📰 Original Source
http://www.zerodayinitiative.com/advisories/ZDI-26-720/ ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Access is where most audits get tested.

Verisq AI Trust Operations maps incidents like this to your access controls and collects the evidence continuously, keeping your trust posture defensible.

See where you'd stand with Verisq AI Trust Operations →