CVE-2026-12057 HIGH

CVE-2026-12057: DoS + Remote Code Execution via PDF JavaScript in Foxit AI

Vendor Foxit Software Inc.
Product Foxit AI
Weakness CWE-829 · Inclusion from untrusted sphere
Published June 15, 2026
Last update June 15, 2026

CVSS base score

8.6/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H

What the vulnerability does

Description

When the application executes the JavaScript script embedded in the PDF within the sandbox, it fails to intercept some dangerous interfaces, which allows remote scripts to be loaded, resulting in arbitrary code execution.

Key dates

Disclosure timeline

June 15, 2026 CVE published
June 15, 2026 Record updated