CVE-2026-5943
Last modified
CVE-2026-5943 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Document structural anomalies caused inconsistencies between page element relationships and internal index states. When scripts triggered document modifications, object reference validity was not properly maintained, leading to a crash when accessing an invalid pointer during page information queries.. EPSS estimates a 0.18% chance of exploitation in the next 30 days.
Description
Document structural anomalies caused inconsistencies between page element relationships and internal index states. When scripts triggered document modifications, object reference validity was not properly maintained, leading to a crash when accessing an invalid pointer during page information queries.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Foxit | Pdf Editor | < 13.2.4 |
| Foxit | Pdf Editor | >= 14.0.0, < 14.0.4 |
| Foxit | Pdf Editor | >= 2023.0.0, < 2026.1.1 |
| Foxit | Pdf Reader | < 2026.1.1 |
References
- https://www.foxit.com/support/security-bulletins.htmlVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-5943?
How severe is CVE-2026-5943?
How do I fix CVE-2026-5943?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-5937Insufficient parameter verification leads to the occurrence …5.5
- CVE-2026-5938Improper control flow management allows a crafted document a…5.5
- CVE-2026-5939A crafted XFA PDF can trigger a use-after-free condition dur…5.5
- CVE-2026-5940Calling a function that triggers a UI refresh after removing…5.5
- CVE-2026-5941Parsing logic flaws cause non-signature data to be misidenti…7.1
- CVE-2026-5942Flaws in page lifecycle management allow document structure …5.5
- CVE-2026-5944An improper access control vulnerability exists in the Cisco…8.2
- CVE-2026-5946Multiple flaws have been identified in `named` related to th…7.5
- CVE-2026-5947Undefined behavior may result due to a race condition leadin…5.9
- CVE-2026-5950An unbounded resend loop vulnerability exists in the BIND 9 …5.3
- CVE-2026-59509An unauthenticated improper input validation vulnerability i…9.2
- CVE-2026-59510AIL Framework contains a path traversal vulnerability in its…7.1
Are you affected by CVE-2026-5943?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
