Insufficient Control Flow Management in Foxit PDF Editor (formerly Foxit PhantomPDF) and Foxit PDF Reader for Windows - CVE-2026-5938
Published: April 27, 2026
Foxit PDF Editor (formerly Foxit PhantomPDF)
Foxit PDF Reader for Windows
Detailed vulnerability description
The vulnerability allows a remote attacker to cause a denial of service.
The vulnerability exists due to improper control flow management in automatic directory imports when handling tasks related to automatic directory imports. A remote attacker can trick the victim into opening a crafted document action chain to cause a denial of service.
User interaction is required to open a crafted document.