medium · CVSS v3 6.1 · EPSS 0.00174
CVE-2026-91796
The interface of Foxit PDF Editor/Reader lacks the permission verification for secure reading mode, which allows special…
Description
The interface of Foxit PDF Editor/Reader lacks the permission verification for secure reading mode, which allows specially crafted PDFs to trigger external SMB authentication without any security prompts and thereby leak the hash of the user's credentials.
Scores
- Severity
- medium
- CVSS v2
- 5.6
- CVSS v3
- 6.1
- CVSS v4
- —
- EPSS
- 0.00174