Self-Modifications Affecting Altered Printing and Redaction in Foxit PDF Editor
Summary
| CVE | CVE-2026-3774 |
|---|---|
| State | PUBLISHED |
| Assigner | Foxit |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-04-01 02:16:02 UTC |
| Updated | 2026-04-10 01:36:58 UTC |
| Description | The application allows PDF JavaScript and document/print actions (such as WillPrint/DidPrint) to update form fields, annotations, or optional content groups (OCGs) immediately before or after redaction, encryption, or printing. These script‑driven updates are not fully covered by the existing redaction, encryption, and printing logic, which, under specific document structures and user workflows, may cause a small amount of sensitive content to remain unremoved or unencrypted as expected, or result in printed output that slightly differs from what was reviewed on screen. |
Risk And Classification
Primary CVSS: v3.1 7.5 HIGH from [email protected]
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
EPSS: 0.000170000 probability, percentile 0.039740000 (date 2026-04-15)
Problem Types: CWE-200 | NVD-CWE-noinfo | CWE-200 CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | [email protected] | Primary | 7.5 | HIGH | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| 3.1 | 14984358-7092-470d-8f34-ade47a7658a2 | Secondary | 4.7 | MEDIUM | CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N |
| 3.1 | CNA | CVSS | 4.7 | MEDIUM | CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
NoneAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Foxit | Pdf Editor | All | All | All | All |
| Application | Foxit | Pdf Editor | All | All | All | All |
| Application | Foxit | Pdf Editor | All | All | All | All |
| Application | Foxit | Pdf Editor | All | All | All | All |
| Application | Foxit | Pdf Editor | All | All | All | All |
| Application | Foxit | Pdf Reader | All | All | All | All |
| Operating System | Microsoft | Windows | - | All | All | All |
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Foxit Software Inc. | Foxit PDF Editor | affected Versions 2025.3 and earlier | Windows |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.foxit.com/support/security-bulletins.html | 14984358-7092-470d-8f34-ade47a7658a2 | www.foxit.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Titus Vollbracht, Sören Borgstedt, Christian Mainka, Vladislav Mladenov (en)
There are currently no legacy QID mappings associated with this CVE.