CVE-2026-91796

The interface of Foxit PDF Editor/Reader lacks the permission verification for secure reading mode, which allows specially crafted PDFs to trigger external SMB authentication without any security prompts and thereby leak the hash of the user's credentials.

  • Published Sep 23, 2026
  • CVSS 6.1 medium
  • 0.1% chance of exploitation in the next 30 days (EPSS)

Affected software

In the news

CVE-2026-91796 at the National Vulnerability Database