Junglewise Threat Intelligence

CVE-2026-13129: Foxit PDF Reader and Editor use-after-free in field traversal

CVE-2026-13129 · Severity: high · CVSS 7.8 · Published 2026-07-08

Executive brief

Foxit PDF Reader and Editor are widely used applications for viewing and managing PDF documents. A vulnerability has been identified where opening a specially crafted PDF file can cause the application to crash or allow an attacker to take control of the system. This could lead to the theft of sensitive information or a disruption of business operations if a user is tricked into opening a malicious file.

Technical details

A use-after-free vulnerability (CWE-416) exists in Foxit PDF Reader and Editor when handling PDF files with damaged field trees. When the application opens such a file, embedded JavaScript triggers a field traversal that causes the program to maintain a reference to an invalid form object. Accessing the property path of this invalid object leads to an invalid pointer read and subsequent memory corruption. An attacker can exploit this by enticing a user to open a malicious PDF, potentially achieving arbitrary code execution or information disclosure. The issue is resolved in version 2026.1.2.

Affected products

  • Foxit Software Inc. Foxit PDF Editor 2026.1.1 and earlier, 14.0.4 and earlier, 13.2.4 and earlier
  • Foxit Software Inc. Foxit PDF Reader 2026.1.1 and earlier

Timeline

  • 2026-07-08: disclosed
  • 2026-07-08: patched: Fixed in version 2026.1.2
  • 2026-07-08: advisory

References