CVE-2026-5939
MEDIUMUAF in Foxit PDF Editor/Reader via XFA calculate event
Title source: cnaDescription
A crafted XFA PDF can trigger a use-after-free condition during calculate event processing, causing the application to crash and resulting in an arbitrary code execution.
References (1)
Scores
CVSS v3
5.5
EPSS
0.0001
EPSS Percentile
3.1%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
total
Details
CWE
CWE-416
Status
published
Products (5)
foxit/pdf_editor
14.0.0 - 14.0.4
foxit/pdf_reader
< 2026.1.1
Foxit Software Inc./Foxit PDF Editor
Versions 14.0.3 and earlier
Foxit Software Inc./Foxit PDF Editor
Versions 2026.1 and earlier
Foxit Software Inc./Foxit PDF Reader
Versions 2026.1 and earlier
Published
Apr 27, 2026
Tracked Since
Apr 27, 2026