ZDI-CAN-29491: ZDI-26-301: Foxit PDF Reader Annotation Use-After-Free Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-5940.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-29491?
ZDI-CAN-29491 has a CVSS rating of 7.8, indicating it is a high-severity vulnerability.
How do I fix ZDI-CAN-29491?
To mitigate ZDI-CAN-29491, ensure that you update to the latest version of Foxit PDF Reader as provided by the vendor.
What type of vulnerability is ZDI-CAN-29491?
ZDI-CAN-29491 is a use-after-free vulnerability that can lead to remote code execution.
What must occur to exploit ZDI-CAN-29491?
Exploitation of ZDI-CAN-29491 requires user interaction; the target must visit a malicious webpage or open a malicious PDF file.
Which software is affected by ZDI-CAN-29491?
ZDI-CAN-29491 affects installations of Foxit PDF Reader.