Junglewise Threat Intelligence

CVE-2026-91796: Foxit PDF Editor and Reader credential hash leakage via SMB

CVE-2026-91796 · Severity: medium · CVSS 6.1 · Published 2026-09-23

Technologies: Foxit PDF Reader, Foxit PDF Editor. Vendors: Foxit.

Executive brief

Foxit PDF Editor and Reader fail to properly verify permissions for secure reading mode, allowing a specially crafted PDF to trigger external SMB authentication without warning the user. An attacker can exploit this to steal the Windows credential hash from users who open a malicious PDF, which can be cracked offline or relayed to compromise the user's account.

Technical details

The vulnerability stems from insufficient permission validation in the secure reading mode interface, allowing JavaScript actions or embedded content in PDFs to initiate SMB connections without user consent or security prompts. An attacker can craft a malicious PDF that, when opened, automatically connects to an attacker-controlled SMB share and captures the user's NTLM credential hash. The affected versions lack proper checks on which external resources may be accessed in secure mode.

Affected products

  • Foxit PDF Reader 2026.2.0.39747 and earlier
  • Foxit PDF Editor 2026.2.0.39747 and all previous 2026.x versions, 2025.3.0.35737 and all previous 2025.x versions, 2024.4.1.27687 and all previous 2024.x versions, 2023.3.0.23028 and all previous 2023.x versions, 14.0.7.33751 and all previous 14.x versions, 13.2.6.24111 and earlier

Timeline

  • 2026-09-23: disclosed
  • 2026-09-23: patched: Foxit PDF Reader 2026.2.1 and Foxit PDF Editor 2026.2.1/14.0.8 released

References

Related threats