Home

Description

Flaws in page lifecycle management allow document structure changes to desynchronize internal component states, causing subsequent operations to access invalidated objects and crash the program.

PUBLISHED Reserved 2026-04-09 | Published 2026-04-27 | Updated 2026-04-27 | Assigner Foxit




MEDIUM: 5.5CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

Problem types

CWE-416 Use after free

Product status

Default status
unaffected

Versions 2026.1 and earlier
affected

Versions 14.0.3 and earlier
affected

Versions 13.2.3 and earlier
affected

Default status
unaffected

Versions 2026.1 and earlier
affected

Credits

Anonymous working with TrendAI Zero Day Initiative finder

References

www.foxit.com/support/security-bulletins.html

cve.org (CVE-2026-5942)

nvd.nist.gov (CVE-2026-5942)

Download JSON