CVE-2026-5938
published 2026-04-27CVE-2026-5938: Improper control flow management allows a crafted document action chain to cause modal dialog reentry on the main thread, resulting in UI freeze and denial of…
PriorityP419medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.10%
1.2th percentile
Improper control flow management allows a crafted document action chain to cause modal dialog reentry on the main thread, resulting in UI freeze and denial of service.
Affected
8 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| foxit | pdf_editor | < 13.2.4 | 13.2.4 |
| foxit | pdf_editor | >= 14.0.0 < 14.0.4 | 14.0.4 |
| foxit | pdf_editor | >= 2023.0.0 < 2026.1.1 | 2026.1.1 |
| foxit | pdf_reader | < 2026.1.1 | 2026.1.1 |
| foxit_software_inc | foxit_pdf_editor | — | — |
| foxit_software_inc | foxit_pdf_editor | — | — |
| foxit_software_inc | foxit_pdf_editor | — | — |
| foxit_software_inc | foxit_pdf_reader | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Foxit PDF Editor/PDF Reader Document Action Chain insufficient control flow management (EUVD-2026-25824 / Nessus ID 310407)
vuldb·2026-04-27·CVSS 5.5
CVE-2026-5938 [MEDIUM] Foxit PDF Editor/PDF Reader Document Action Chain insufficient control flow management (EUVD-2026-25824 / Nessus ID 310407)
A vulnerability was found in Foxit PDF Editor and PDF Reader. It has been declared as problematic. This issue affects some unknown processing of the component Document Action Chain Handler. Such manipulation leads to insufficient control flow management.
This vulnerability is uniquely identified as CVE-2026-5938. The attack can be launched remotely. No exploit exists.
GHSA
GHSA-7r3x-9grv-cr95: Improper control flow management allows a crafted document action chain to cause modal dialog reentry on the main thread, resulting in UI freeze and d
ghsa_unreviewed·2026-04-27
CVE-2026-5938 [MEDIUM] CWE-691 GHSA-7r3x-9grv-cr95: Improper control flow management allows a crafted document action chain to cause modal dialog reentry on the main thread, resulting in UI freeze and d
Improper control flow management allows a crafted document action chain to cause modal dialog reentry on the main thread, resulting in UI freeze and denial of service.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2026-04-27
Published