{"id":"CVE-2026-91796","title":"The interface of Foxit PDF Editor/Reader lacks the permission verification for secure reading mode, which allows specially crafted PDFs to trigger external SMB authentication without any security prompts and thereby leak the hash of the …","summary":"The interface of Foxit PDF Editor/Reader lacks the permission verification for secure reading mode, which allows specially crafted PDFs to trigger external SMB authentication without any security prompts and thereby leak the hash of the …","severity":"medium","cvss":6.1,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H","cwe":["CWE-693"],"vendor":"Foxit Software Inc.","product":"Foxit PDF Editor","affected":["foxit_pdf_editor Versions 2026.2 and earlier","foxit_pdf_editor Versions 14.0.7 and earlier","foxit_pdf_editor Versions 13.2.6 and earlier","foxit_pdf_reader Versions 2026.2 and earlier"],"published":"2026-09-23","updated":"2026-09-23","sourceUpdated":"2026-09-23T17:58:26.570","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-91796","references":[{"url":"https://www.foxit.com/support/security-bulletins.html","label":"14984358-7092-470d-8f34-ade47a7658a2"}],"tags":["nvd","cve.org"],"epss":0.00174,"epssPercentile":0.07213,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"partial","timestamp":"2026-09-23T14:46:24.585625Z"},"ingestedAt":"2026-09-23T08:20:37.587Z","slug":"CVE-2026-91796","body":"## Overview\n\nThe interface of Foxit PDF Editor/Reader lacks the permission verification for secure reading mode, which allows specially crafted PDFs to trigger external SMB authentication without any security prompts and thereby leak the hash of the user's credentials.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":34,"depthScoreParts":{"impact":33.6,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}