Home

Description

Calling a function that triggers a UI refresh after removing comments via a script may access an invalidated object, leading to program crashes.

PUBLISHED Reserved 2026-04-09 | Published 2026-04-27 | Updated 2026-04-28 | Assigner Foxit




HIGH: 7.8CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Problem types

CWE-416 Use after free

Product status

Default status
unaffected

Versions 2026.1 and earlier
affected

Versions 14.0.3 and earlier
affected

Versions 13.2.3 and earlier
affected

Default status
unaffected

Versions 2026.1 and earlier
affected

Credits

Anonymous working with TrendAI Zero Day Initiative finder

References

www.foxit.com/support/security-bulletins.html

cve.org (CVE-2026-5940)

nvd.nist.gov (CVE-2026-5940)

Download JSON