2026-04-27 11:0CVE-2026-5943Foxit
PUBLISHED5.2CWE-416

Foxit PDF Editor/Reader AcroForm Annotation Use-After-Free Remote Code Execution Vulnerability

Document structural anomalies caused inconsistencies between page element relationships and internal index states. When scripts triggered document modifications, object reference validity was not properly maintained, leading to a crash when accessing an invalid pointer during page information queries.

Problem type

Affected products

Foxit Software Inc.

Foxit PDF Editor

Versions 2026.1 and earlier - AFFECTED

Versions 14.0.3 and earlier - AFFECTED

Versions 13.2.3 and earlier - AFFECTED

Foxit PDF Reader

Versions 2026.1 and earlier - AFFECTED

References

GitHub Security Advisories

GHSA-8hgx-6h8v-fcg8

Document structural anomalies caused inconsistencies between page element relationships and...

https://github.com/advisories/GHSA-8hgx-6h8v-fcg8

Document structural anomalies caused inconsistencies between page element relationships and internal index states. When scripts triggered document modifications, object reference validity was not properly maintained, leading to a crash when accessing an invalid pointer during page information queries.

JSON source

https://cveawg.mitre.org/api/cve/CVE-2026-5943
Click to expand
{
  "dataType": "CVE_RECORD",
  "dataVersion": "5.2",
  "cveMetadata": {
    "cveId": "CVE-2026-5943",
    "assignerOrgId": "14984358-7092-470d-8f34-ade47a7658a2",
    "assignerShortName": "Foxit",
    "dateUpdated": "2026-04-27T11:00:31.554Z",
    "dateReserved": "2026-04-09T03:42:20.240Z",
    "datePublished": "2026-04-27T11:00:31.554Z",
    "state": "PUBLISHED"
  },
  "containers": {
    "cna": {
      "providerMetadata": {
        "orgId": "14984358-7092-470d-8f34-ade47a7658a2",
        "shortName": "Foxit",
        "dateUpdated": "2026-04-27T11:00:31.554Z"
      },
      "title": "Foxit PDF Editor/Reader AcroForm Annotation Use-After-Free Remote Code Execution Vulnerability",
      "descriptions": [
        {
          "lang": "en",
          "value": "Document structural anomalies caused inconsistencies between page element relationships and internal index states. When scripts triggered document modifications, object reference validity was not properly maintained, leading to a crash when accessing an invalid pointer during page information queries.",
          "supportingMedia": [
            {
              "type": "text/html",
              "base64": false,
              "value": "Document structural anomalies caused inconsistencies between page element relationships and internal index states. When scripts triggered document modifications, object reference validity was not properly maintained, leading to a crash when accessing an invalid pointer during page information queries."
            }
          ]
        }
      ],
      "affected": [
        {
          "vendor": "Foxit Software Inc.",
          "product": "Foxit PDF Editor",
          "platforms": [
            "Windows"
          ],
          "defaultStatus": "unaffected",
          "versions": [
            {
              "version": "Versions 2026.1 and earlier",
              "status": "affected"
            },
            {
              "version": "Versions 14.0.3 and earlier",
              "status": "affected"
            },
            {
              "version": "Versions 13.2.3 and earlier",
              "status": "affected"
            }
          ]
        },
        {
          "vendor": "Foxit Software Inc.",
          "product": "Foxit PDF Reader",
          "defaultStatus": "unaffected",
          "versions": [
            {
              "version": "Versions 2026.1 and earlier",
              "status": "affected"
            }
          ]
        }
      ],
      "problemTypes": [
        {
          "descriptions": [
            {
              "lang": "en",
              "description": "CWE-416 Use after free",
              "cweId": "CWE-416",
              "type": "CWE"
            }
          ]
        }
      ],
      "references": [
        {
          "url": "https://www.foxit.com/support/security-bulletins.html"
        }
      ],
      "impacts": [
        {
          "descriptions": [
            {
              "lang": "en",
              "value": "Potential arbitrary code execution"
            }
          ]
        }
      ],
      "metrics": [
        {
          "format": "CVSS",
          "scenarios": [
            {
              "lang": "en",
              "value": "GENERAL"
            }
          ],
          "cvssV3_1": {
            "version": "3.1",
            "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
            "attackVector": "LOCAL",
            "attackComplexity": "LOW",
            "privilegesRequired": "NONE",
            "userInteraction": "REQUIRED",
            "scope": "UNCHANGED",
            "confidentialityImpact": "HIGH",
            "integrityImpact": "HIGH",
            "availabilityImpact": "HIGH",
            "baseScore": 7.8,
            "baseSeverity": "HIGH"
          }
        }
      ],
      "credits": [
        {
          "lang": "en",
          "value": "Anonymous working with TrendAI Zero Day Initiative",
          "type": "finder"
        }
      ]
    }
  }
}