CVE-2026-5936 is a Server-Side Request Forgery (SSRF) vulnerability that allows authenticated attackers to manipulate server-side HTTP requests by supplying specially crafted URLs, enabling the server to initiate requests to arbitrary destinations. The vulnerability poses significant risk for probing internal network services, accessing cloud metadata services, and circumventing network access controls, with potential for sensitive information disclosure and lateral movement within affected environments. The vulnerability carries a HIGH CVSS score of 8.5, reflecting its serious nature. The attack requires network access and low attack complexity, though it does require valid user credentials (low privilege level), making it accessible to authenticated users. The scope is changed, meaning impacts extend beyond the vulnerable component, with high confidentiality impact and limited integrity impact possible. The FAUCET Risk Score of 51.0 indicates moderate concern. There is currently no evidence of active exploitation in the wild, as indicated by its absence from the Known Exploited Vulnerabilities (KEV) catalog and inactive status on threat tracking lists. The extremely low EPSS score of 0.00032 suggests minimal probability of exploitation in real-world scenarios at this time. However, organizations should prioritize patching this vulnerability given its high CVSS rating and the straightforward nature of SSRF attacks once exploits become available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2026-04-07CPE matchmatch criteria | cpe:2.3:a:foxit:pdf_services_api:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.