Junglewise Threat Intelligence

CVE-2026-57251: Foxit PDF Reader and Editor out-of-bounds access in cloud appearance construction

CVE-2026-57251 · Severity: high · CVSS 7.8 · Published 2026-07-08

Executive brief

Foxit PDF Reader and Editor are widely used applications for viewing and modifying PDF documents. A vulnerability in how these applications handle specific visual construction processes could allow an attacker to crash the software or potentially gain unauthorized access to data. This typically requires a user to open a specially crafted, malicious PDF file.

Technical details

The vulnerability is classified as an Improper Validation of Array Index (CWE-129). It occurs during the construction of 'cloud-like' appearances within a PDF, where the application fails to implement proper upper limits and consistency checks on underlying arrays. An attacker can exploit this by providing a malformed PDF that triggers an out-of-bounds access. While the primary reported impact is an application crash, the CVSS 3.1 vector (AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H) suggests potential for arbitrary code execution or information disclosure. The issue is fixed in Foxit PDF Reader/Editor version 2026.1.2.

Affected products

  • Foxit Software Inc. Foxit PDF Editor 2026.1.1 and earlier, 14.0.4 and earlier, 13.2.4 and earlier
  • Foxit Software Inc. Foxit PDF Reader 2026.1.1 and earlier

Timeline

  • 2026-07-08: disclosed
  • 2026-07-08: patched: Fixed in version 2026.1.2

References