VYPR
advisoryPublished Sep 23, 2026· 14 sources

Foxit PDF Reader Vulnerable to Information Disclosure via Doc Object Flaw

A new vulnerability in Foxit PDF Reader allows remote attackers to disclose sensitive information by exploiting a flaw in its Doc Object component.

A vulnerability has been disclosed in Foxit PDF Reader that could allow remote attackers to reveal sensitive information from affected systems. The flaw resides within the software's Doc Object component, a part of the application responsible for handling document-related functionalities.

Exploitation of this vulnerability requires a degree of user interaction. Attackers cannot remotely trigger the vulnerability without the victim's involvement. Specifically, a user must either open a specially crafted malicious file or visit a malicious webpage that hosts the exploit. This user-driven action is a prerequisite for the information disclosure to occur.

The Zero Day Initiative (ZDI), a prominent vulnerability research and disclosure organization, has assigned the identifier ZDI-26-739 to this flaw. They have also assigned a Common Vulnerability Scoring System (CVSS) rating of 3.3, categorizing it as a low-severity vulnerability. This low score reflects the limited impact and the requirement for user interaction.

In conjunction with the ZDI advisory, a Common Vulnerabilities and Exposures (CVE) identifier has been assigned: CVE-2026-91810. This CVE number will serve as a unique identifier for the vulnerability in public vulnerability databases and security advisories.

While the vulnerability allows for information disclosure, the specific types of sensitive data that could be exfiltrated are not detailed in the initial advisories. However, such vulnerabilities in PDF readers can sometimes lead to the exposure of system information, configuration details, or potentially parts of other documents processed by the reader.

Foxit PDF Reader is a widely used application for viewing, editing, and signing PDF documents. Its broad user base means that even low-severity vulnerabilities can affect a significant number of individuals and organizations. Users are advised to ensure they are running the latest version of the software to mitigate potential risks.

As this is a disclosed vulnerability, users should check for and apply any available patches or updates released by Foxit. Staying informed about security advisories and maintaining up-to-date software are crucial steps in defending against such information disclosure threats.

The Zero Day Initiative has disclosed a new vulnerability, ZDI-26-732, affecting Foxit PDF Reader. This flaw, assigned CVE-2026-91796, specifically targets the importIcon function, allowing remote attackers to disclose NTLM responses. While the existing story covers a general information disclosure via the Doc Object component, this new advisory details a distinct vulnerability with a lower CVSS score of 3.3, requiring user interaction through a malicious webpage or file.

This advisory details a specific out-of-bounds read vulnerability (CVE-2026-91808) within Foxit PDF Reader's JPEG file parsing mechanism. The vulnerability allows remote attackers to disclose sensitive information by tricking a user into opening a crafted file or visiting a malicious webpage, with a CVSS rating of 3.3.

This advisory details a specific information disclosure vulnerability within Foxit PDF Reader's activeDocs component, identified as ZDI-26-720. The flaw stems from a lack of authorization in the JavaScript API, allowing attackers to disclose contents of other open documents. The Zero Day Initiative has assigned CVE-2026-91788 to this issue, which has a CVSS score of 4.7 and requires user interaction to exploit.

This new advisory, ZDI-26-745, details a distinct vulnerability within Foxit PDF Reader's AcroForm component, differing from the previously reported Doc Object flaw. The current vulnerability, CVE-2026-91817, is an out-of-bounds read that allows for remote code execution, whereas the prior advisory focused on information disclosure. Both vulnerabilities require user interaction and have been addressed by Foxit with security updates.

The new advisory, ZDI-26-738, details a specific use-after-free vulnerability within Foxit PDF Reader's Annotation objects, distinct from the Doc Object flaw mentioned in the existing story. This newly disclosed vulnerability, CVE-2026-91809, also allows for information disclosure but has a lower CVSS score of 3.3 and requires user interaction.

This advisory, ZDI-26-736, details a specific out-of-bounds read vulnerability (CVE-2026-91807) within Foxit PDF Reader's file parsing mechanism. Unlike the previously reported Doc Object flaw, this vulnerability specifically targets the handling of PDF files, allowing remote attackers to disclose sensitive information by tricking users into opening a malicious file or visiting a malicious webpage. Foxit has released an update to address this particular issue.

The Zero Day Initiative advisory ZDI-26-735 details a use-after-free vulnerability within Foxit PDF Reader's handling of Doc objects. This specific flaw, assigned CVE-2026-91806, allows for sensitive information disclosure and requires user interaction for exploitation, such as opening a malicious PDF or visiting a compromised webpage. The vulnerability has been assigned a CVSS score of 3.3.

Zero Day Initiative has disclosed a new critical remote code execution vulnerability, ZDI-26-731, affecting Foxit PDF Reader. This flaw stems from an uninitialized variable within the FileOpen component, enabling attackers to execute arbitrary code in the context of the current process. Exploitation requires user interaction, such as opening a malicious PDF or visiting a compromised webpage, and the vulnerability carries a CVSS score of 7.8.

The Zero Day Initiative advisory ZDI-26-729 provides further technical details on this Foxit PDF Reader vulnerability, assigning it the identifier CVE-2026-91793. It specifies that the flaw lies within the handling of Doc objects, stemming from a failure to validate an object's existence before operations are performed. While the vulnerability itself leads to information disclosure, it can be chained with other flaws to achieve arbitrary code execution.

The Zero Day Initiative advisory ZDI-26-728 details a use-after-free vulnerability within Foxit PDF Reader's Doc object handling. This specific flaw, assigned CVE-2026-57238, allows for sensitive information disclosure and requires user interaction for exploitation, such as opening a malicious file or visiting a compromised webpage. While the original advisory did not explicitly mention the CVE, this new information provides a specific identifier for the vulnerability.

The Zero Day Initiative advisory ZDI-26-726 details a use-after-free vulnerability affecting Foxit PDF Reader's handling of Doc objects. This specific flaw, assigned CVE-2026-13129, allows remote attackers to disclose sensitive information, though it requires user interaction such as opening a crafted PDF. Foxit has since released an update to address this vulnerability.

This advisory, ZDI-26-725, details a specific use-after-free vulnerability within Foxit PDF Reader's handling of Doc objects. While the existing story broadly covers information disclosure via a Doc Object flaw, this new information specifies the exact mechanism as a failure to validate an object's existence before operations, which could also lead to arbitrary code execution in conjunction with other vulnerabilities. The Zero Day Initiative has assigned this vulnerability the identifier CVE-2026-57256 and a CVSS score of 3.3.

The Zero Day Initiative advisory ZDI-26-723 details a use-after-free vulnerability in Foxit PDF Reader's Doc object handling, assigned CVE-2026-91790. This new advisory specifies that the vulnerability allows remote attackers to disclose sensitive information, and it requires user interaction such as opening a malicious file or visiting a compromised webpage. The Zero Day Initiative has assigned this vulnerability a CVSS score of 3.3.

Synthesized by Vypr AI