Description
After the application opened the PDF file, the script first reset the annotation status, then triggered the reset form event by additional action. During the re-entry process, the application access invalid objects and crashed.
Published: 2026-07-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a use‑after‑free flaw in Foxit’s PDF Editor and Reader that triggers during the processing of a PDF file. When a PDF is opened, the application resets annotation status and then fires a reset form event; during the subsequent re‑entry it accesses objects that have already been freed, causing a crash. This memory safety error results in an abrupt termination of the application and is classified as CWE‑416.

Affected Systems

Foxit PDF Editor and Foxit PDF Reader are affected. No specific version numbers are supplied by the CNA; administrators should verify that their deployments are running the most recent releases.

Risk and Exploitability

The CVSS score of 7.8 indicates high severity. The EPSS score is below 1%, reflecting a very low but non‑zero probability of exploitation, and the vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is remote; a malicious PDF document that an end‑user opens could trigger the flaw. Given the lack of additional constraints, the vulnerability is potentially exploitable by an attacker who can deliver a crafted PDF to a victim’s machine.

Generated by OpenCVE AI on July 29, 2026 at 14:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Foxit PDF Editor/Reader patch to address the use‑after‑free flaw.
  • Disable JavaScript and scripting in PDF files to reduce the attack surface.
  • Restrict document processing to trusted sources and monitor for abnormal crashes.

Generated by OpenCVE AI on July 29, 2026 at 14:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Foxitsoftware
Foxitsoftware foxit Pdf Editor
Foxitsoftware foxit Reader
Vendors & Products Foxitsoftware
Foxitsoftware foxit Pdf Editor
Foxitsoftware foxit Reader

Wed, 08 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Description After the application opened the PDF file, the script first reset the annotation status, then triggered the reset form event by additional action. During the re-entry process, the application access invalid objects and crashed.
Title Foxit PDF Editor/Reader Annotation Use-After-Free Vulnerability
Weaknesses CWE-416
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Foxitsoftware Foxit Pdf Editor Foxit Reader
cve-icon MITRE

Status: PUBLISHED

Assigner: Foxit

Published:

Updated: 2026-07-08T12:40:28.820Z

Reserved: 2026-06-24T03:01:18.717Z

Link: CVE-2026-57249

cve-icon Vulnrichment

Updated: 2026-07-08T12:40:23.498Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T14:45:02Z

Weaknesses