CVE-2026-57246
published 2026-07-08CVE-2026-57246: When dealing with abnormally constructed objects, there is a lack of argument validation; JavaScript triggers signature verification, but the signature plugin…
PriorityP335high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.15%
4.5th percentile
When dealing with abnormally constructed objects, there is a lack of argument validation; JavaScript triggers signature verification, but the signature plugin does not perform validation when copying the abnormal string, causing the application to crash.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| foxit | pdf_editor | <= 13.2.4.24048 | — |
| foxit | pdf_editor | 14.0.0.33046 – 14.0.4.33508 | — |
| foxit | pdf_editor | 2023.1.0.15510 – 2023.3.0.23028 | — |
| foxit | pdf_editor | 2024.1.0.23997 – 2024.4.1.27687 | — |
| foxit | pdf_editor | 2025.1.0.27937 – 2025.3.0.35737 | — |
| foxit | pdf_editor | 2026.1.0.36452 – 2026.1.1.36485 | — |
| foxit | pdf_reader | <= 2026.1.1.36485 | — |
| foxit_software_inc | foxit_pdf_editor | — | — |
| foxit_software_inc | foxit_pdf_editor | — | — |
| foxit_software_inc | foxit_pdf_editor | — | — |
| foxit_software_inc | foxit_pdf_reader | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
When dealing with abnormally constructed objects, there is a lack of argument validation; JavaScript triggers signature verification, but the signature plugin does not perform validation when copying
ghsa_unreviewed·2026-07-08
CVE-2026-57246 [HIGH] CWE-120 When dealing with abnormally constructed objects, there is a lack of argument validation; JavaScript triggers signature verification, but the signature plugin does not perform validation when copying
When dealing with abnormally constructed objects, there is a lack of argument validation; JavaScript triggers signature verification, but the signature plugin does not perform validation when copying the abnormal string, causing the application to crash.
VulDB
Foxit PDF Editor/PDF Reader Signature Plugin signature verification (WID-SEC-2026-2241)
vuldb·2026-07-08·CVSS 7.8
CVE-2026-57246 [HIGH] Foxit PDF Editor/PDF Reader Signature Plugin signature verification (WID-SEC-2026-2241)
A vulnerability classified as problematic was found in Foxit PDF Editor and PDF Reader. Impacted is an unknown function of the component Signature Plugin. Executing a manipulation can lead to improper verification of cryptographic signature.
This vulnerability is registered as CVE-2026-57246. It is possible to launch the attack remotely. No exploit is available.
No detection rules found.
No public exploits indexed.
2026-07-08
Published