The interface of Foxit PDF Editor/Reader lacks the permission verification for secure reading mode, which allows specially crafted PDFs to trigger external SMB authentication without any security prompts and thereby leak the hash of the user's credentials.
Project Subscriptions
No data.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://www.foxit.com/support/security-bulletins.html |
|
History
Wed, 23 Sep 2026 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The interface of Foxit PDF Editor/Reader lacks the permission verification for secure reading mode, which allows specially crafted PDFs to trigger external SMB authentication without any security prompts and thereby leak the hash of the user's credentials. | |
| Title | Foxit PDF Editor/Reader importIcon NTLM Response Information Disclosure Vulnerability | |
| Weaknesses | CWE-693 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: Foxit
Published:
Updated: 2026-09-23T07:51:02.709Z
Reserved: 2026-09-15T07:34:40.287Z
Link: CVE-2026-91796
No data.
Status : Received
Published: 2026-09-23T08:17:11.570
Modified: 2026-09-23T08:17:11.570
Link: CVE-2026-91796
No data.
OpenCVE Enrichment
No data.
Weaknesses