high · CVSS v3 7.8
CVE-2026-91795
Addressed a potential issue where the application could be exposed to an Untrusted Pointer Dereference vulnerability whe…
Description
Addressed a potential issue where the application could be exposed to an Untrusted Pointer Dereference vulnerability when opening a crafted PDF containing a malicious FOPN_foweb encryption filter with the FileOpen plugin, which attackers could exploit to execute arbitrary code. This occurs due to a lack of proper validation of the encryption metadata, leaving an internal pointer in an invalid state and resulting in chained read and write access violations.
Scores
- Severity
- high
- CVSS v2
- 6.8
- CVSS v3
- 7.8
- CVSS v4
- —
- EPSS
- —