CVSS 7.8 · HIGH
CVE-2026-5941
Parsing logic flaws cause non-signature data to be misidentified as valid signatures when processing malformed form field hierarchies, leading to invalid memory writes and program crashes during internal data structure construction.
View on NVDAnalysis
Foxit PDF Reader and Editor are vulnerable to memory corruption when processing specially crafted PDF documents with malformed form fields. Opening a malicious file could lead to application crashes or potentially allow an attacker to execute arbitrary code on the victim's machine.
Severity
Score: 7.8(HIGH)
Vector:
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HAV: LOCAL
AC: LOW
PR: NONE
UI: REQUIRED
S: UNCHANGED
C: HIGH
I: HIGH
A: HIGH
Weakness (CWE):
CWE-20NVD-CWE-noinfoEPSS
Probability of exploitation (next 30 days): 0.0003 (0.0%)
Percentile: 8.3%
EPSS: 2026-05-06
Affects
foxit:pdf_editorfoxit:pdf_readerTechnical description
Parsing logic flaws cause non-signature data to be misidentified as valid signatures when processing malformed form field hierarchies, leading to invalid memory writes and program crashes during internal data structure construction.
Published: 4/27/2026, 12:16:24 PM
Last modified: 4/29/2026, 5:24:15 PM