Information Disclosure in Foxit PDF Reader (CVE‑2026‑91788) Enables Sensitive Document Exposure
What It Is – A missing‑authorization flaw in the JavaScript API of Foxit PDF Reader allows a remote attacker, who convinces a user to open a malicious PDF or visit a crafted web page, to read the contents of other documents that the user has open.
Exploitability – Requires user interaction (malicious file or page). No public exploit code is known, and the CVSS v3.1 base score is 4.7 (moderate).
Affected Products – Foxit PDF Reader (all versions prior to the September 2026 security update).
Why It Matters for Trust & Control Assurance
- Demonstrates the need for authorization enforcement controls that verify a user’s right to access any application‑level function.
- Highlights the importance of continuous patch monitoring as evidence of due‑diligence for auditors.
- Shows that application‑level logging of JavaScript API calls can provide a defensible audit trail when a breach investigation is required.
Recommended Actions
- Deploy Foxit’s September 2026 security update immediately.
- Review and harden the JavaScript API usage policy on all PDF‑handling workstations.
- Enable detailed logging of PDF‑related events and integrate logs into your SIEM for continuous monitoring.
- Validate that your access‑control matrix includes “document‑view” permissions for PDF applications.