CVE 7.8 HIGH

Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulnerability_CVE-2026-5940

7.8 / 10
HIGH
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Description

Calling a function that triggers a UI refresh after removing comments via a script may access an invalidated object, leading to program crashes.

Basic Information

ID CVE-2026-5940
Source Foxit
Published Apr 27, 2026 at 11:00

Affected Product

Vendor Foxit Software Inc.
Product Foxit PDF Editor
Version Versions 2026.1 and earlier
Affected Versions Foxit Software Inc. Foxit PDF Editor Versions 2026.1 and earlier
Foxit Software Inc. Foxit PDF Editor Versions 14.0.3 and earlier
Foxit Software Inc. Foxit PDF Editor Versions 13.2.3 and earlier
Foxit Software Inc. Foxit PDF Reader Versions 2026.1 and earlier

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.