rootpwn

medium · CVSS v3 6.1 · EPSS 0.00174

CVE-2026-91796

The interface of Foxit PDF Editor/Reader lacks the permission verification for secure reading mode, which allows special…

Description

The interface of Foxit PDF Editor/Reader lacks the permission verification for secure reading mode, which allows specially crafted PDFs to trigger external SMB authentication without any security prompts and thereby leak the hash of the user's credentials.

Scores

Severity
medium
CVSS v2
5.6
CVSS v3
6.1
CVSS v4
EPSS
0.00174

← All CVEs