CVE-2026-57260
Analyzed
Analyzed - Analysis Complete
Unity 3D Object Parsing Pointer Dereference Vulnerability
Vulnerability report for CVE-2026-57260, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-07-08
Last updated on: 2026-07-09
Assigner: Foxit
Description
Description
The application opened a PDF file containing an abnormal Unity 3D object. During parsing, the application incorrectly resolved a portion of the abnormal object as a pointer and used it as a valid address, ultimately causing the application to crash.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| foxit | pdf_editor | From 2023.1.0.15510 (inc) to 2023.3.0.23028 (inc) |
| foxit | pdf_editor | From 2024.1.0.23997 (inc) to 2024.4.1.27687 (inc) |
| foxit | pdf_editor | From 2025.1.0.27937 (inc) to 2025.3.0.35737 (inc) |
| foxit | pdf_editor | From 2026.1.0.36452 (inc) to 2026.1.1.36485 (inc) |
| foxit | pdf_reader | to 2026.1.1.36485 (inc) |
| foxit | pdf_editor | to 13.2.4.24048 (inc) |
| foxit | pdf_editor | From 14.0.0.33046 (inc) to 14.0.4.33508 (inc) |
| foxit | pdf_editor | From 2023.1.0.55583 (inc) to 2023.3.0.63083 (inc) |
| foxit | pdf_editor | From 2024.1.0.63682 (inc) to 2024.4.1.66479 (inc) |
| foxit | pdf_editor | From 2025.1.0.66692 (inc) to 2025.3.0.69570 (inc) |
| foxit | pdf_editor | to 13.2.3.63444 (inc) |
| foxit | pdf_reader | to 2026.1.1.70276 (inc) |
| foxit | pdf_editor | From 14.0.0.68868 (inc) to 14.0.3.69295 (inc) |
| foxit | pdf_editor | From 2026.1.0.70169 (inc) to 2026.1.1.70276 (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-787 | The product writes data past the end, or before the beginning, of the intended buffer. |