CVE-2026-91796 MEDIUM

CVE-2026-91796: Foxit PDF Editor/Reader importIcon NTLM Response Information Disclosure Vulnerability

Vendor Foxit Software Inc.
Product Foxit PDF Editor
Weakness CWE-693
Published September 23, 2026
Last update September 23, 2026

CVSS base score

6.1/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality Low
Integrity None

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H

What the vulnerability does

01Description

The interface of Foxit PDF Editor/Reader lacks the permission verification for secure reading mode, which allows specially crafted PDFs to trigger external SMB authentication without any security prompts and thereby leak the hash of the user's credentials.

Key dates

02Disclosure timeline

September 23, 2026 CVE published

Related vulnerabilities

04Related CVE