Description
There is an abnormal annotation within the PDF that is referenced by other objects. When the application parses the PDF, it fails to perform proper type checking, ultimately causing the application to crash.
Published: 2026-07-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability arises when a PDF contains an abnormal annotation that is referenced by other objects. When the application parses the PDF, it fails to perform proper type checking, ultimately causing the program to crash. The failure to validate the annotation type maps to CWE‑843. The resulting crash leads to a denial‑of‑service condition where the victim’s PDF viewer becomes unavailable.

Affected Systems

The issue affects Foxit PDF Editor and Foxit PDF Reader. No specific version range is mentioned, so all released versions may potentially be affected until a patch is applied.

Risk and Exploitability

The CVSS score of 7.8 classifies the flaw as high‑severity. The EPSS score of <1% indicates a low likelihood of exploitation, and the lack of KEV listing suggests no widespread exploitation yet. Attackers could still deliver malicious PDFs via email or the web, exploiting local user interaction to trigger the crash, but the precise delivery method is not explicitly described in the CVE text. The description implies that a malicious PDF opened by a user is likely the attack vector, as the vulnerability triggers during PDF parsing. Because the effect is only a crash, there is no direct code execution, but the high severity coupled with the ease of delivery makes it a significant risk for environments that rely on Foxit for document handling.

Generated by OpenCVE AI on July 29, 2026 at 14:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the latest security patch for Foxit PDF Editor and Foxit PDF Reader from the official Foxit support site.
  • Enable automatic updates for Foxit products so that future patches are applied automatically.
  • Restrict PDF opening privileges for untrusted users and employ email or web gateway filtering to block or quarantine suspicious PDFs.

Generated by OpenCVE AI on July 29, 2026 at 14:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 09:45:00 +0000

Type Values Removed Values Added
First Time appeared Foxitsoftware
Foxitsoftware foxit Pdf Editor
Foxitsoftware foxit Reader
Vendors & Products Foxitsoftware
Foxitsoftware foxit Pdf Editor
Foxitsoftware foxit Reader

Wed, 08 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Description There is an abnormal annotation within the PDF that is referenced by other objects. When the application parses the PDF, it fails to perform proper type checking, ultimately causing the application to crash.
Title Foxit PDF Editor/Reader Annotation Type Confusion Vulnerability
Weaknesses CWE-843
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Foxitsoftware Foxit Pdf Editor Foxit Reader
cve-icon MITRE

Status: PUBLISHED

Assigner: Foxit

Published:

Updated: 2026-07-08T12:46:02.325Z

Reserved: 2026-06-24T03:01:18.718Z

Link: CVE-2026-57254

cve-icon Vulnrichment

Updated: 2026-07-08T12:45:58.726Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T14:45:02Z

Weaknesses
  • CWE-843

    Access of Resource Using Incompatible Type ('Type Confusion')