CVE-2026-91796

Summary

The interface of Foxit PDF Editor/Reader lacks the permission verification for secure reading mode, which allows specially crafted PDFs to trigger external SMB authentication without any security prompts and thereby leak the hash of the user's credentials.

Affected Software

VendorProductVersion RangeStatus
Foxit Software Inc.Foxit PDF EditorVersions 2026.2 and earlieraffected
Foxit Software Inc.Foxit PDF EditorVersions 14.0.7 and earlieraffected
Foxit Software Inc.Foxit PDF EditorVersions 13.2.6 and earlieraffected
Foxit Software Inc.Foxit PDF ReaderVersions 2026.2 and earlieraffected

Weaknesses

  • CWE-693: CWE-693:Protection Mechanism Failure

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References