Junglewise Threat Intelligence

CVE-2026-57252: Foxit PDF Reader and Editor use-after-free in attachment panel

CVE-2026-57252 · Severity: high · CVSS 7.8 · Published 2026-07-08

Executive brief

Foxit PDF Reader and Editor are widely used applications for viewing and modifying PDF documents. A security vulnerability has been identified where opening a specially crafted PDF file can cause the application to crash or allow an attacker to gain control over the system. This could lead to the theft of sensitive information or the installation of malicious software if a user is tricked into opening a malicious document.

Technical details

A Use-After-Free (CWE-416) vulnerability exists in Foxit PDF Reader and Editor when processing JavaScript within a PDF file. The flaw occurs during the deletion of pages and removal of attachment annotations, where the attachment panel continues to access invalid pointers. An attacker can exploit this by enticing a user to open a malformed PDF, leading to a crash or potential arbitrary code execution in the context of the current user. The vulnerability is triggered because the application fails to properly validate objects or pointers after they have been modified by JavaScript. Foxit has addressed this issue in version 2026.1.2.

Affected products

  • Foxit Software Inc. Foxit PDF Reader 2026.1.1.36485 and earlier
  • Foxit Software Inc. Foxit PDF Editor 2026.1.1.36485 and all previous 2026.x versions, 2025.3.0.35737 and all previous 2025.x versions, 2024.4.1.27687 and all previous 2024.x versions, 2023.3.0.23028 and all previous 2023.x versions, 14.0.4.33508 and all previous 14.x version, 13.2.4.24048 and earlier

Timeline

  • 2026-07-08: disclosed
  • 2026-07-08: patched
  • 2026-07-08: advisory

References