CVE-2026-57259: Foxit PDF Editor/Reader XDP XFA XXE arbitrary local file read
The input file does not need to be strictly in a structurally valid PDF format. Instead, after reviewing the content, the original document disguised as a PDF will be sent to the parser. Malicious documents will construct malicious external entities that, through the protocol, point to local paths, thereby allowing access to any local files within the user's permission range.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-57259?
CVE-2026-57259 has a medium severity rating of 6.5.
What is the impact of exploiting CVE-2026-57259?
Exploiting CVE-2026-57259 can lead to arbitrary local file reading through crafted malicious documents.
How do I fix CVE-2026-57259?
To fix CVE-2026-57259, ensure you are using the latest version of Foxit PDF Editor or Reader that addresses this vulnerability.
Which software is affected by CVE-2026-57259?
CVE-2026-57259 affects Foxit PDF Editor and Foxit PDF Reader.
What type of vulnerability is CVE-2026-57259 classified as?
CVE-2026-57259 is classified as an XML External Entity (XXE) vulnerability.