CVE-2026-12057
Last modified
CVE-2026-12057 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. When the application executes the JavaScript script embedded in the PDF within the sandbox, it fails to intercept some dangerous interfaces, which allows remote scripts to be loaded, resulting in arbitrary code execution.. EPSS estimates a 0.13% chance of exploitation in the next 30 days.
Description
When the application executes the JavaScript script embedded in the PDF within the sandbox, it fails to intercept some dangerous interfaces, which allows remote scripts to be loaded, resulting in arbitrary code execution.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Foxit | Ai | < 2026-06-15 |
References
- https://www.foxit.com/support/security-bulletins.htmlVendor Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-12057?
How severe is CVE-2026-12057?
How do I fix CVE-2026-12057?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-12048Stored cross-site scripting in pgAdmin 4's error-rendering a…5.4
- CVE-2026-12049Open redirect in pgAdmin 4's multi-factor authentication flo…6.1
- CVE-2026-12050SQL injection in pgAdmin 4's named restore point endpoint (P…8.8
- CVE-2026-12051The USB DFU class implementation in Zephyr's new (experiment…4.6
- CVE-2026-12052The USB device-side CDC NCM class control-to-host handler us…5.2
- CVE-2026-12053GitLab has remediated an issue in GitLab EE affecting all ve…7.5
- CVE-2026-12058The connection confirmation pop-up of a specific feature in …5.3
- CVE-2026-12059The SSH service of CelloOS developed by Cellopoint has an Im…8.8
- CVE-2026-1206The Elementor Website Builder plugin for WordPress is vulner…4.3
- CVE-2026-12060Heptabase developed by Hepta Platforms has a Exposed Dangero…6.9
- CVE-2026-12064When a user invokes curl using a schemeless URL combined wit…7.5
- CVE-2026-12065A vulnerability was identified in Groww Stock, Mutual Fund, …1.8
Are you affected by CVE-2026-12057?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
