{ "dataType": "CVE_RECORD", "dataVersion": "5.2", "cveMetadata": { "cveId": "CVE-2026-91796", "assignerOrgId": "14984358-7092-470d-8f34-ade47a7658a2", "state": "PUBLISHED", "assignerShortName": "Foxit", "dateReserved": "2026-09-15T07:34:40.287Z", "datePublished": "2026-09-23T07:51:02.709Z", "dateUpdated": "2026-09-23T14:46:30.859Z" }, "containers": { "cna": { "providerMetadata": { "orgId": "14984358-7092-470d-8f34-ade47a7658a2", "shortName": "Foxit", "dateUpdated": "2026-09-23T07:51:02.709Z" }, "title": "Foxit PDF Editor/Reader importIcon NTLM Response Information Disclosure Vulnerability", "problemTypes": [ { "descriptions": [ { "lang": "en", "cweId": "CWE-693", "description": "CWE-693:Protection Mechanism Failure", "type": "CWE" } ] } ], "impacts": [ { "descriptions": [ { "lang": "en", "value": "Information Disclosure" } ] } ], "affected": [ { "vendor": "Foxit Software Inc.", "product": "Foxit PDF Editor", "platforms": [ "Windows" ], "versions": [ { "status": "affected", "version": "Versions 2026.2 and earlier" }, { "status": "affected", "version": "Versions 14.0.7 and earlier" }, { "status": "affected", "version": "Versions 13.2.6 and earlier" } ], "defaultStatus": "unaffected" }, { "vendor": "Foxit Software Inc.", "product": "Foxit PDF Reader", "platforms": [ "Windows" ], "versions": [ { "status": "affected", "version": "Versions 2026.2 and earlier" } ], "defaultStatus": "unaffected" } ], "descriptions": [ { "lang": "en", "value": "The interface of Foxit PDF Editor/Reader lacks the permission verification for secure reading mode, which allows specially crafted PDFs to trigger external SMB authentication without any security prompts and thereby leak the hash of the user's credentials.", "supportingMedia": [ { "type": "text/html", "base64": false, "value": "The interface of Foxit PDF Editor/Reader lacks the permission verification for secure reading mode, which allows specially crafted PDFs to trigger external SMB authentication without any security prompts and thereby leak the hash of the user's credentials." } ] } ], "references": [ { "url": "https://www.foxit.com/support/security-bulletins.html" } ], "metrics": [ { "format": "CVSS", "scenarios": [ { "lang": "en", "value": "GENERAL" } ], "cvssV3_1": { "version": "3.1", "attackVector": "LOCAL", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "REQUIRED", "scope": "UNCHANGED", "confidentialityImpact": "LOW", "integrityImpact": "NONE", "availabilityImpact": "HIGH", "baseSeverity": "MEDIUM", "baseScore": 6.1, "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:H" } } ], "credits": [ { "lang": "en", "value": "Liang Zhu working with TrendAI Zero Day Initiative", "type": "finder" } ], "x_generator": { "engine": "Vulnogram 1.0.5" } }, "adp": [ { "metrics": [ { "other": { "type": "ssvc", "content": { "timestamp": "2026-09-23T14:46:24.585625Z", "id": "CVE-2026-91796", "options": [ { "Exploitation": "none" }, { "Automatable": "no" }, { "Technical Impact": "partial" } ], "role": "CISA Coordinator", "version": "2.0.3" } } } ], "title": "CISA ADP Vulnrichment", "providerMetadata": { "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2026-09-23T14:46:30.859Z" } } ] } }