Description
The application opened a PDF file containing an abnormal Unity 3D object. During parsing, the application incorrectly resolved a portion of the abnormal object as a pointer and used it as a valid address, ultimately causing the application to crash.
Published: 2026-07-08
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw lies in the U3D Adobe Mesh Decompression routine used by Foxit PDF Editor and Reader. When the software parses a PDF that contains an abnormal Unity 3D object, it mistakenly treats part of the object data as a pointer and dereferences it as an address. This invalid memory access triggers a crash, preventing further use of the application. The weakness is a CWE‑787 and results in a denial‑of‑service scenario for the end user.

Affected Systems

Foxit Software Inc.’s PDF Editor and PDF Reader products are affected. The CVE record does not list specific vulnerable version ranges, so any installation of either product before the latest vendor update that patches the U3D de‑compression path could be impacted.

Risk and Exploitability

The CVSS score of 7.8 indicates a high risk level, while the EPSS score is recorded as less than 1% (0.0017), suggesting that exploitation events are currently rare. The vulnerability is not listed in CISA’s KEV catalog. The most likely attack vector involves a malicious PDF file containing a malformed Unity 3D object; when a user opens the file, the application crashes. The exploit does not provide code execution or privilege escalation, but it does allow an attacker to cause service disruption and disrupt user productivity.

Generated by OpenCVE AI on July 28, 2026 at 09:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply any available Foxit update that patches the U3D Adobe Mesh Decompression path, which resolves the memory corruption issue (CWE‑787).
  • If a patch is not yet released, configure the application to disable or block Unity 3D object support in the settings, which reduces the chances of the vulnerability being triggered.
  • Exercise caution by avoiding opening PDF files from untrusted or unknown sources, and verify the credibility of documents before opening them.

Generated by OpenCVE AI on July 28, 2026 at 09:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
First Time appeared Foxitsoftware
Foxitsoftware foxit Pdf Editor
Foxitsoftware foxit Reader
Vendors & Products Foxitsoftware
Foxitsoftware foxit Pdf Editor
Foxitsoftware foxit Reader

Wed, 08 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 08:30:00 +0000

Type Values Removed Values Added
Description The application opened a PDF file containing an abnormal Unity 3D object. During parsing, the application incorrectly resolved a portion of the abnormal object as a pointer and used it as a valid address, ultimately causing the application to crash.
Title Security vulnerability in Foxit PDF Editor/Reader — U3D Adobe Mesh Decompression (Type Confusion / Invalid Pointer Dereference)
Weaknesses CWE-787
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Subscriptions

Foxitsoftware Foxit Pdf Editor Foxit Reader
cve-icon MITRE

Status: PUBLISHED

Assigner: Foxit

Published:

Updated: 2026-07-08T12:47:34.866Z

Reserved: 2026-06-24T03:01:24.249Z

Link: CVE-2026-57260

cve-icon Vulnrichment

Updated: 2026-07-08T12:47:29.049Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T09:30:19Z

Weaknesses