CVE-2026-57259
Analyzed
Analyzed - Analysis Complete
External Entity Attack in PDF Disguised Document
Vulnerability report for CVE-2026-57259, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-07-08
Last updated on: 2026-07-09
Assigner: Foxit
Description
Description
The input file does not need to be strictly in a structurally valid PDF format. Instead, after reviewing the content, the original document disguised as a PDF will be sent to the parser. Malicious documents will construct malicious external entities that, through the protocol, point to local paths, thereby allowing access to any local files within the user's permission range.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| foxit | pdf_editor | From 2023.1.0.15510 (inc) to 2023.3.0.23028 (inc) |
| foxit | pdf_editor | From 2024.1.0.23997 (inc) to 2024.4.1.27687 (inc) |
| foxit | pdf_editor | From 2025.1.0.27937 (inc) to 2025.3.0.35737 (inc) |
| foxit | pdf_editor | From 2026.1.0.36452 (inc) to 2026.1.1.36485 (inc) |
| foxit | pdf_reader | to 2026.1.1.36485 (inc) |
| foxit | pdf_editor | to 13.2.4.24048 (inc) |
| foxit | pdf_editor | From 14.0.0.33046 (inc) to 14.0.4.33508 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-611 | The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output. |