← back
CVE-2026-57259mediumCWE-611

Foxit PDF Editor/Reader XDP XFA XXE arbitrary local file read

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.5epss 0.2%
exploitation probability
0.2%top 88% of all CVEs
observed exploitation
nono source reports it
The input file does not need to be strictly in a structurally valid PDF format. Instead, after reviewing the content, the original document disguised as a PDF will be sent to the parser. Malicious documents will construct malicious external entities that, through the protocol, point to local paths, thereby allowing access to any local files within the user's permission range.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N