CVE 5.5 MEDIUM

UAF in Foxit PDF Editor/Reader via XFA calculate event_CVE-2026-5939

5.5 / 10
MEDIUM
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Description

A crafted XFA PDF can trigger a use-after-free condition during calculate event processing, causing the application to crash and resulting in an arbitrary code execution.

Basic Information

ID CVE-2026-5939
Source Foxit
Published Apr 27, 2026 at 11:00

Affected Product

Vendor Foxit Software Inc.
Product Foxit PDF Editor
Version Versions 2026.1 and earlier
Affected Versions Foxit Software Inc. Foxit PDF Editor Versions 2026.1 and earlier
Foxit Software Inc. Foxit PDF Editor Versions 14.0.3 and earlier
Foxit Software Inc. Foxit PDF Reader Versions 2026.1 and earlier

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.