JavaScript Execution Flaw in PDF Application by Foxit
CVE-2026-57256

7.8HIGH

Key Information:

Vendor

Foxit Inc.

Vendor
CVE Published:
8 July 2026

What is CVE-2026-57256?

CVE-2026-57256 is a vulnerability identified in a PDF application developed by Foxit Inc., known for its products designed to create, edit, and manage PDF files. This vulnerability manifests when the application opens a PDF containing JavaScript, leading to abnormal operations on form fields, particularly list boxes. The failure to properly validate the integrity of form objects and their associated dictionary pointers allows the application to attempt to access invalid or uninitialized memory locations. As a result, this can cause the application to crash unexpectedly, posing risks to organizational workflows and potentially exposing sensitive data if the application hangs or becomes unresponsive during critical operations.

Potential Impact of CVE-2026-57256

  1. Application Crashes: The improper handling and validation of memory pointers can lead to frequent application crashes, disrupting user access to essential PDF functionalities and causing downtime.

  2. Data Integrity Risks: The potential for accessing invalid memory locations may result in data corruption or loss, particularly if users are interacting with important files during the occurrence of the vulnerability, jeopardizing the integrity of critical information.

  3. Security Exposure: While there is currently no known exploitation of this vulnerability, the existence of such a flaw raises concerns over potential future attacks. Attackers could craft malicious PDFs to trigger the vulnerability, potentially leading to unauthorized access or control over the application environment.

Affected Version(s)

Foxit PDF Editor MacOS Versions 2026.1.1 and earlier

Foxit PDF Editor MacOS Versions 14.0.3 and earlier

Foxit PDF Editor Windows Versions 2026.1.1 and earlier

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

KPC of Cisco Talos
.