CVE-2026-57248
published 2026-07-08CVE-2026-57248: When the application opens a PDF file and JavaScript writes annotation attributes, there is a lack of sufficient object type and argument checks. As a result…
PriorityP334high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.15%
4.4th percentile
When the application opens a PDF file and JavaScript writes annotation attributes, there is a lack of sufficient object type and argument checks. As a result, due to the damage to the internal structure of the annotations, it causes the application to crash during subsequent release.
Affected
11 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| foxit | pdf_editor | <= 13.2.4.24048 | — |
| foxit | pdf_editor | 14.0.0.33046 – 14.0.4.33508 | — |
| foxit | pdf_editor | 2023.1.0.15510 – 2023.3.0.23028 | — |
| foxit | pdf_editor | 2024.1.0.23997 – 2024.4.1.27687 | — |
| foxit | pdf_editor | 2025.1.0.27937 – 2025.3.0.35737 | — |
| foxit | pdf_editor | 2026.1.0.36452 – 2026.1.1.36485 | — |
| foxit | pdf_reader | <= 2026.1.1.36485 | — |
| foxit_software_inc | foxit_pdf_editor | — | — |
| foxit_software_inc | foxit_pdf_editor | — | — |
| foxit_software_inc | foxit_pdf_editor | — | — |
| foxit_software_inc | foxit_pdf_reader | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
VulDB
Foxit PDF Editor/PDF Reader PDF file (WID-SEC-2026-2241)
vuldb·2026-07-09·CVSS 7.8
CVE-2026-57248 [HIGH] Foxit PDF Editor/PDF Reader PDF file (WID-SEC-2026-2241)
A vulnerability was found in Foxit PDF Editor and PDF Reader. It has been classified as problematic. The impacted element is an unknown function of the component PDF file Handler. This manipulation causes an unknown weakness.
This vulnerability is handled as CVE-2026-57248. It is possible to launch the attack on the local host. There is not any exploit available.
GHSA
When the application opens a PDF file and JavaScript writes annotation attributes, there is a lack of sufficient object type and argument checks.
ghsa_unreviewed·2026-07-08
CVE-2026-57248 [HIGH] CWE-763 When the application opens a PDF file and JavaScript writes annotation attributes, there is a lack of sufficient object type and argument checks.
When the application opens a PDF file and JavaScript writes annotation attributes, there is a lack of sufficient object type and argument checks. As a result, due to the damage to the internal structure of the annotations, it causes the application to crash during subsequent release.
No detection rules found.
No public exploits indexed.
2026-07-08
Published