Skip to main content
Vulnerability Database/CVE-2026-91796

CVE-2026-91796: Foxit PDF Editor Credential Hash Leak

CVE-2026-91796 is an information disclosure flaw in Foxit PDF Editor/Reader that bypasses secure reading mode protections. Malicious PDFs can trigger SMB authentication to steal credential hashes. This article covers technical details, affected versions, security impact, and mitigation strategies.

Published:

CVE-2026-91796 Overview

CVE-2026-91796 affects Foxit PDF Editor and Foxit PDF Reader. The interface lacks permission verification for secure reading mode. A specially crafted PDF can trigger external Server Message Block (SMB) authentication requests without displaying any security prompts to the user. This behavior causes the Windows client to send NTLM authentication material to an attacker-controlled server, leaking the hash of the user's credentials. The flaw is categorized as a security feature bypass under [CWE-693].

Critical Impact

An attacker who convinces a user to open a malicious PDF can capture NTLM credential hashes suitable for offline cracking or relay attacks, enabling downstream account compromise.

Affected Products

  • Foxit PDF Editor (Windows)
  • Foxit PDF Reader (Windows)
  • Refer to the Foxit Security Bulletins for specific affected versions

Discovery Timeline

  • 2026-09-23 - CVE-2026-91796 published to the National Vulnerability Database (NVD)
  • 2026-09-23 - Last updated in NVD database

Technical Details for CVE-2026-91796

Vulnerability Analysis

The vulnerability resides in how Foxit PDF Editor and Reader enforce secure reading mode. Secure reading mode is intended to gate risky operations, including outbound network requests initiated by PDF content, behind user consent. The application interface does not verify permission before allowing embedded references to resolve to remote SMB paths. As a result, opening a crafted document causes Windows to perform an SMB authentication handshake against a host controlled by the attacker.

During this handshake, the Windows client automatically transmits the current user's NTLM credential material. The attacker captures the challenge and response, then performs offline cracking or forwards the credentials in an NTLM relay attack against internal services.

Root Cause

The root cause is missing enforcement of the secure reading mode policy on interface-level actions that initiate outbound resource resolution. Under [CWE-693] Protection Mechanism Failure, a protective control exists but is not consistently applied. The prompt that should warn the user about external network access is skipped, so the attack proceeds silently.

Attack Vector

Exploitation requires user interaction. An attacker delivers a crafted PDF via email, chat, a web download, or a network share. When the victim opens the document in a vulnerable Foxit build on Windows, the reader dereferences an embedded UNC path such as \\attacker.example.com\share\file. The operating system resolves the path over SMB and negotiates authentication using the current user context. No dialog warns the victim that outbound authentication is occurring.

Because no verified proof-of-concept code has been published, this article does not include exploit code. Technical detail on the specific interface routine is available in the Foxit Security Bulletins.

Detection Methods for CVE-2026-91796

Indicators of Compromise

  • Outbound SMB traffic on TCP 445 or 139 originating from a workstation immediately after a PDF is opened
  • DNS lookups from FoxitPDFReader.exe or FoxitPDFEditor.exe for external, non-corporate hostnames
  • NTLM NTLMSSP_AUTH messages sent to hosts outside the internal file server allow list
  • PDF files containing UNC-style references or remote form action URLs pointing to unfamiliar servers

Detection Strategies

  • Alert on any process image matching FoxitPD*.exe that establishes a network connection to a remote address on ports 445, 139, or 80/443 for WebDAV
  • Correlate PDF open events in Windows Application logs with subsequent outbound SMB session establishment
  • Inspect email and web gateway telemetry for PDFs containing external UNC references before delivery

Monitoring Recommendations

  • Enable process and network telemetry on Windows endpoints where Foxit is installed
  • Log NTLM authentication attempts on domain controllers and review outbound authentication targets
  • Monitor egress firewalls for SMB traffic leaving the corporate perimeter and treat any hit as high priority

How to Mitigate CVE-2026-91796

Immediate Actions Required

  • Inventory all Windows systems running Foxit PDF Editor or Reader and identify versions in use
  • Block outbound SMB traffic (TCP 445 and 139) at the perimeter firewall for all user workstations
  • Restrict NTLM authentication to remote servers using the Group Policy setting Network security: Restrict NTLM: Outgoing NTLM traffic to remote servers
  • Instruct users to avoid opening PDF attachments from untrusted senders until patching is complete

Patch Information

Foxit publishes fixed builds through its advisory portal. Review the Foxit Security Bulletins for the patched version corresponding to CVE-2026-91796 and deploy it through your standard software distribution mechanism.

Workarounds

  • Enforce secure reading mode through group policy and verify the setting is applied on every endpoint
  • Disable automatic loading of external resources within Foxit PDF preferences where the option is exposed
  • Apply the Windows registry key RestrictSendingNTLMTraffic set to 2 (Deny all) on high-risk workstations after testing compatibility
bash
# Configuration example: block outbound SMB via Windows Firewall
netsh advfirewall firewall add rule name="Block Outbound SMB 445" dir=out action=block protocol=TCP remoteport=445
netsh advfirewall firewall add rule name="Block Outbound SMB 139" dir=out action=block protocol=TCP remoteport=139

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.