JavaScript Execution Flaw in PDF Reader Software by Foxit
CVE-2026-12057

8.6HIGH

Key Information:

Vendor

Foxit Inc.

Status
Vendor
CVE Published:
15 June 2026

What is CVE-2026-12057?

A security vulnerability in Foxit's PDF Reader allows executed JavaScript scripts embedded within PDFs to bypass sandbox restrictions. This weakness permits remote scripts to be loaded and executed without proper interception, leading to potential arbitrary code execution. Users of impacted versions are strongly urged to apply security updates to mitigate these risks.

Affected Version(s)

Foxit AI before 2026-06-15

References

CVSS V3.1

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

mrfathoni
.