← Back to search

CVE-2026-91796

6.1 MEDIUM

Published 2026-09-23 · Updated 2026-09-23

AI analysis for this CVE has not been generated yet. Raw NVD data is shown below.

NVD description

The interface of Foxit PDF Editor/Reader lacks the permission verification for secure reading mode, which allows specially crafted PDFs to trigger external SMB authentication without any security prompts and thereby leak the hash of the user's credentials.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H

Weaknesses

CWE-693

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.

Related CVEs

Related by shared AI tags and CWE weakness class. Browse the full archive.