Description
The embedded JavaScript in the PDF deleted the pages, making the object invalid. The application attempted to perform a write operation on the invalid pop-up annotations, resulting in the program crashing.
Published: 2026-07-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw arises when an embedded JavaScript section of a PDF deletes internal pages, causing annotation objects to become invalid. The application then tries to write to these invalid annotations, which triggers a crash. The description mentions a use‑after‑free condition that could potentially allow remote code execution, but the official statement only reports a crash, so the primary impact is denial of service. This conclusion is inferred from the lack of any mention of code execution beyond the crash.

Affected Systems

Foxit PDF Editor and Foxit PDF Reader are affected. The CNA did not list any specific versions, so all released releases of these products may contain the flaw, pending vendor verification.

Risk and Exploitability

The CVSS score of 7.8 labels the vulnerability as high severity, while the EPSS score of less than 1% indicates a very low probability of exploitation in the wild. The flaw is not listed in CISA’s KEV catalog. The most likely attack scenario involves a malicious PDF delivered via email, download, or any medium that can embed malicious JavaScript, since the vulnerability is triggered by the viewer’s handling of that PDF. No evidence in the description indicates that an attacker can gain arbitrary code execution; the outcome described is application crash.

Generated by OpenCVE AI on July 29, 2026 at 14:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Foxit PDF Editor or Foxit PDF Reader patch that fixes the CWE‑416 use‑after‑free flaw.
  • Disable JavaScript execution in PDF files to prevent the embedded script from running.
  • Avoid opening PDFs from untrusted sources or run the viewer in a sandbox or isolated environment.

Generated by OpenCVE AI on July 29, 2026 at 14:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Foxitsoftware
Foxitsoftware foxit Pdf Editor
Foxitsoftware foxit Reader
Vendors & Products Foxitsoftware
Foxitsoftware foxit Pdf Editor
Foxitsoftware foxit Reader

Wed, 08 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Description The embedded JavaScript in the PDF deleted the pages, making the object invalid. The application attempted to perform a write operation on the invalid pop-up annotations, resulting in the program crashing.
Title Foxit PDF Editor/Reader Annotation Use-After-Free Remote Code Execution Vulnerability
Weaknesses CWE-416
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Foxitsoftware Foxit Pdf Editor Foxit Reader
cve-icon MITRE

Status: PUBLISHED

Assigner: Foxit

Published:

Updated: 2026-07-08T12:13:27.791Z

Reserved: 2026-06-24T03:01:45.197Z

Link: CVE-2026-13126

cve-icon Vulnrichment

Updated: 2026-07-08T12:13:07.848Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T14:45:02Z

Weaknesses