CVE-2026-5942

MEDIUM

Foxit PDF Editor/Reader AcroForm Signature Use-After-Free Vulnerability

Title source: cna
STIX 2.1

Description

Flaws in page lifecycle management allow document structure changes to desynchronize internal component states, causing subsequent operations to access invalidated objects and crash the program.

Scores

CVSS v3 5.5
EPSS 0.0001
EPSS Percentile 2.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-416
Status published
Products (6)
foxit/pdf_editor < 13.2.4
foxit/pdf_reader < 2026.1.1
Foxit Software Inc./Foxit PDF Editor Versions 13.2.3 and earlier
Foxit Software Inc./Foxit PDF Editor Versions 14.0.3 and earlier
Foxit Software Inc./Foxit PDF Editor Versions 2026.1 and earlier
Foxit Software Inc./Foxit PDF Reader Versions 2026.1 and earlier
Published Apr 27, 2026
Tracked Since Apr 27, 2026