CVE-2026-91796
6.1Foxit Software · Foxit PDF Editor, Foxit PDF Reader
Foxit PDF Editor and Reader fail to verify permissions in secure reading mode, allowing malicious PDF files to trigger unauthorized SMB authentication and leak user credential hashes.
Executive summary
A vulnerability in Foxit PDF Editor and Reader allows an attacker to force unauthorized SMB authentication, potentially resulting in the theft of user credential hashes.
Vulnerability
This is a protection mechanism failure where the application fails to enforce secure reading mode permissions. An unauthenticated attacker can craft a malicious PDF that triggers external SMB authentication without user interaction, leading to credential hash exposure.
Business impact
The exposure of NTLM or other credential hashes poses a significant risk to organizational security, as these hashes can be cracked offline or used in relay attacks to gain unauthorized access to internal network resources. While the CVSS score of 6.1 represents a medium severity, the potential for lateral movement following a credential harvest warrants prompt attention to protect sensitive user identity data.
Remediation
Immediate Action: Update all installations of Foxit PDF Editor and Foxit PDF Reader to the latest available versions provided by the vendor.
Proactive Monitoring: Review network egress logs for unexpected SMB traffic originating from workstations running PDF software.
Compensating Controls: Disable NTLM authentication at the network level or enforce SMB signing/encryption via Group Policy to prevent the utility of captured hashes in relay attacks.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Organizations should prioritize patching Foxit PDF software across all endpoints to mitigate this credential exposure risk. Given the ease with which users can be phished into opening malicious PDF files, applying the vendor updates is the most effective way to restore secure reading mode protections and prevent unauthorized authentication attempts.
More Foxit Software CVEs all →
History
- Analyst report written
Sources
Originally found and disclosed by Liang Zhu working with TrendAI Zero Day Initiative, per the CVE Program record.