rootpwn

high · CVSS v3 7.8

CVE-2026-91795

Addressed a potential issue where the application could be exposed to an Untrusted Pointer Dereference vulnerability whe…

Description

Addressed a potential issue where the application could be exposed to an Untrusted Pointer Dereference vulnerability when opening a crafted PDF containing a malicious FOPN_foweb encryption filter with the FileOpen plugin, which attackers could exploit to execute arbitrary code. This occurs due to a lack of proper validation of the encryption metadata, leaving an internal pointer in an invalid state and resulting in chained read and write access violations.

Scores

Severity
high
CVSS v2
6.8
CVSS v3
7.8
CVSS v4
EPSS

← All CVEs