---
id: CVE-2026-91796
title: >-
  The interface of Foxit PDF Editor/Reader lacks the permission verification for
  secure reading mode, which allows specially crafted PDFs to trigger external
  SMB authentication without any security prompts and thereby leak the hash of
  the …
summary: >-
  The interface of Foxit PDF Editor/Reader lacks the permission verification for
  secure reading mode, which allows specially crafted PDFs to trigger external
  SMB authentication without any security prompts and thereby leak the hash of
  the …
severity: medium
cvss: 6.1
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H'
cwe:
  - CWE-693
vendor: Foxit Software Inc.
product: Foxit PDF Editor
affected:
  - foxit_pdf_editor Versions 2026.2 and earlier
  - foxit_pdf_editor Versions 14.0.7 and earlier
  - foxit_pdf_editor Versions 13.2.6 and earlier
  - foxit_pdf_reader Versions 2026.2 and earlier
published: '2026-09-23'
updated: '2026-09-23'
sourceUpdated: '2026-09-23T17:58:26.570'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-91796'
references:
  - url: 'https://www.foxit.com/support/security-bulletins.html'
    label: 14984358-7092-470d-8f34-ade47a7658a2
tags:
  - nvd
  - cve.org
epss: 0.00121
epssPercentile: 0.0165
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-23T14:46:24.585625Z'
ingestedAt: '2026-09-23T08:20:37.587Z'
---

## Overview

The interface of Foxit PDF Editor/Reader lacks the permission verification for secure reading mode, which allows specially crafted PDFs to trigger external SMB authentication without any security prompts and thereby leak the hash of the user's credentials.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
