Junglewise Threat Intelligence

CVE-2026-57246: Foxit PDF Reader and Editor buffer overflow in signature plugin

CVE-2026-57246 · Severity: high · CVSS 7.8 · Published 2026-07-08

Executive brief

Foxit PDF Reader and Editor are popular applications used for viewing and modifying PDF documents. A security vulnerability has been identified where the software fails to properly validate data when processing specific PDF files containing malformed signature fields or annotations. If a user is tricked into opening a specially crafted PDF, an attacker could potentially crash the application or execute unauthorized code on the user's computer.

Technical details

A 'Buffer Copy without Checking Size of Input' (CWE-120) vulnerability exists in Foxit PDF Reader and Editor. The flaw is triggered when the application handles abnormally constructed objects within a PDF, specifically during signature verification triggered by JavaScript. The signature plugin fails to perform argument validation when copying abnormal strings, leading to a buffer overflow. An attacker can exploit this by providing a malformed PDF file that requires user interaction (opening the file) to trigger the crash or potential arbitrary code execution. The issue is addressed in versions 2026.1.2 and later.

Affected products

  • Foxit Software Inc. Foxit PDF Editor 2026.1.1 and earlier, 14.0.4 and earlier, 13.2.4 and earlier
  • Foxit Software Inc. Foxit PDF Reader 2026.1.1 and earlier

Timeline

  • 2026-07-08: advisory
  • 2026-07-08: patched

References