FoxitCVE-2026-91796
Foxit PDF: protection mechanism failure
Medium6.1CVE-2026-91796 · Published Sep 23, 2026
The interface of Foxit PDF Editor/Reader lacks the permission verification for secure reading mode, which allows specially crafted PDFs to trigger external SMB authentication without any security prompts and thereby leak the hash of the user's credentials.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| Foxit PDF Editor Product | <= Versions 2026.2 and earlier | No fix yet |
| <= Versions 14.0.7 and earlier | No fix yet | |
| <= Versions 13.2.6 and earlier | No fix yet | |
| Foxit PDF Reader Product | <= Versions 2026.2 and earlier | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H
- Severity from
- the vendor (its own CVE record or advisory)
- Weakness
- CWE-693
More Foxit advisories
All Foxit| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 23 | Foxit PDF: out-of-bounds read | Medium6.1 | No fix yet |
| Sep 23 | Foxit PDF: use after free | High7.8 | No fix yet |
| Sep 23 | Foxit PDF: use after free | High7.8 | No fix yet |
| Sep 23 | Foxit PDF: out-of-bounds read | Medium6.1 | No fix yet |
| Sep 23 | Foxit PDF: out-of-bounds write | High7.8 | No fix yet |
| Sep 23 | Foxit PDF: code execution | High7.9 | No fix yet |