
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-5942 is a Use After Free (CWE-416) vulnerability in Foxit PDF Reader and Foxit PDF Editor that allows a local, unauthenticated attacker to crash the application by opening a specially crafted PDF document. Flaws in page lifecycle management allow document structure changes to desynchronize internal component states, causing subsequent operations to access invalidated (freed) objects and crash the program. Affected versions include Foxit PDF Reader prior to 2026.1.1, Foxit PDF Editor prior to 13.2.4, versions 14.0.0–14.0.3 (fixed in 14.0.4), and versions 2023.0.0 through 2026.1.0 (fixed in 2026.1.1). The vulnerability was published on April 27, 2026, with a CVSS v3.1 base score of 5.5 (Medium) (GitHub Advisory, Foxit Security Bulletins).
The root cause is a Use After Free condition (CWE-416) in Foxit's page lifecycle management logic. When a PDF document's structure is modified during page lifecycle transitions, internal component states become desynchronized, leaving dangling pointers to freed memory objects. Subsequent operations that dereference these invalidated pointers trigger an abnormal program termination. Exploitation requires local access and user interaction — specifically, a victim must open a maliciously crafted PDF file. A ZDI advisory (ZDI-26-303) references this vulnerability, though no detailed technical write-up or public PoC code has been confirmed (GitHub Advisory, ZDI Advisory).
Successful exploitation results in a Denial of Service (DoS) — specifically, an application crash of Foxit PDF Reader or PDF Editor. There is no impact on confidentiality or data integrity, as the vulnerability only affects availability (CVSS availability impact: High). The scope is limited to the affected application process; there is no evidence of potential for lateral movement, privilege escalation, or data exfiltration based on current analysis (GitHub Advisory, Foxit Security Bulletins).
No confirmed exploit or proof-of-concept code is publicly available for CVE-2026-5942. A ZDI advisory (ZDI-26-303) was published on April 27, 2026, but analysis of the advisory content found no actionable exploit details or reproduction steps. There is no evidence of in-the-wild exploitation, no threat actor attribution, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. The EPSS score is approximately 0.013–0.015%, placing it in the 3rd percentile for exploitation likelihood (ZDI Advisory, GitHub Advisory).
Foxit has released patched versions addressing this vulnerability. Users should update to the following versions or later: Foxit PDF Reader 2026.1.1, Foxit PDF Editor 13.2.4 (for versions prior to 13.x), Foxit PDF Editor 14.0.4 (for versions 14.0.0–14.0.3), or Foxit PDF Editor 2026.1.1 (for versions 2023.0.0 and above). As an interim workaround where immediate patching is not possible, restrict users from opening untrusted or unknown PDF documents. Updates are available via the Foxit security bulletins page (Foxit Security Bulletins, GitHub Advisory).
The vulnerability received routine coverage from vulnerability tracking platforms and security aggregators shortly after disclosure on April 27, 2026. A Mastodon post from @netsecio noted the CVE, and it was included in a weekly threat landscape digest for Week 18 of 2026 by Hawk-Eye. No significant vendor statements beyond the Foxit security bulletin, notable researcher commentary, or major media coverage have been identified for this moderate-severity DoS vulnerability.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."