ZDI-26-726: Foxit PDF Reader Doc Object Use-After-Free Information Disclosure Vulnerability
ZDI disclosed another Foxit PDF Reader use-after-free, CVE-2026-13129, that can disclose information after user interaction.
The Zero Day Initiative published ZDI-26-726, another Doc object use-after-free information disclosure in Foxit PDF Reader, tracked as CVE-2026-13129. Remote attackers can disclose sensitive information only when the user visits a malicious page or opens a malicious file. ZDI assigned CVSS 3.3. No active exploitation is mentioned.
- CVE-2026-13129 is a separate Doc object use-after-free in Foxit PDF Reader.
- Exploitation requires the victim to open a malicious page or file.
- ZDI assigned CVSS 3.3 for information disclosure.
Vulnerabilities mentionedAll →
- CVE-2026-131297.8<1%When the application opens a PDF file, JavaScript uses the damaged field tree to trigger field traversal, resulting in the program holding an invalid form…published · foxit pdf editor
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-13129 | When the application opens a PDF file, JavaScript uses the damaged field tree to trigger field traversal, resulting in the program holding an invalid form… When the application opens a PDF file, JavaScript uses the damaged field tree to trigger field traversal, resulting in the program holding an invalid form object when accessing the field property path. Eventually, the application crashes due to reading an invalid pointer. |
This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-13129.
This source does not provide full text. Read it at zerodayinitiative.com.