CVE-2026-3774
Foxit PDF Reader vulnerability analysis and mitigation

Overview

CVE-2026-3774 is a sensitive information exposure vulnerability in Foxit PDF Editor and PDF Reader, classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). The flaw allows PDF JavaScript and document/print actions (such as WillPrint/DidPrint) to update form fields, annotations, or optional content groups (OCGs) immediately before or after redaction, encryption, or printing operations, potentially causing sensitive content to bypass these protections. Affected products include Foxit PDF Editor versions up to 13.2.2.24014, 2023.1.0.15510–2023.3.0.23028, 2024.1.0.23997–2024.4.1.27687, 14.0.0.33046–14.0.2.33402, 2025.1.0.27937–2025.3.0.35737, and Foxit PDF Reader up to 2025.3.0.35737. The vulnerability was published on April 1, 2026, with a CVSS v3.1 base score of 4.7 (Moderate) per the GitHub Advisory Database, though an alternative NVD scoring of 7.5 (High) has also been noted (GitHub Advisory, Foxit Security Bulletins).

Technical details

The root cause is classified under CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). Foxit PDF Editor and Reader permit embedded PDF JavaScript event handlers — specifically document/print lifecycle hooks such as WillPrint and DidPrint — to modify form fields, annotations, or Optional Content Groups (OCGs) at the precise moment redaction, encryption, or printing operations are executed. Because these script-driven updates occur outside the scope of the redaction and encryption logic, the application fails to account for last-moment content changes, allowing a small amount of sensitive content to remain unredacted or unencrypted, or causing printed output to differ from the on-screen preview. Exploitation requires a locally accessible, specially crafted PDF document and user interaction (opening and performing redaction/encryption/printing actions) under specific document structures and workflows (GitHub Advisory, Foxit Security Bulletins).

Impact

Successful exploitation results in a confidentiality breach where sensitive content that was intended to be redacted or encrypted may remain exposed in the output document or printed material. An attacker who crafts a malicious PDF and delivers it to a user performing redaction or encryption workflows could cause confidential data — such as personally identifiable information, financial data, or classified content — to persist in an unprotected state. There is no integrity or availability impact; the vulnerability is limited to unauthorized disclosure of sensitive information (GitHub Advisory, Foxit Security Bulletins).

Exploitation steps

  1. Craft a malicious PDF: Create a PDF document containing embedded JavaScript that hooks into document/print lifecycle events (e.g., WillPrint, DidPrint, or field calculation scripts) to dynamically modify form fields, annotations, or OCG visibility immediately before or after a redaction or print operation.
  2. Embed sensitive content manipulation: Design the JavaScript payload to reveal or restore hidden/redacted content (e.g., toggling OCG visibility or updating annotation content) at the precise moment the redaction or encryption function is invoked by the application.
  3. Deliver the document: Distribute the crafted PDF to a target user who is expected to perform redaction, encryption, or printing of sensitive content — for example, via email, shared drive, or document management system.
  4. Trigger the vulnerable workflow: The victim opens the PDF in Foxit PDF Editor or Reader and performs a redaction, encryption, or print operation. The embedded JavaScript executes during the operation's lifecycle hooks, causing sensitive content to bypass redaction/encryption controls.
  5. Obtain exposed content: The resulting output document or printed material contains sensitive data that was not properly redacted or encrypted, which the attacker can then access if they have access to the output file or printed copy (GitHub Advisory).

Indicators of compromise

  • File System: PDF documents containing JavaScript with references to WillPrint, DidPrint, app.doc.print, or OCG manipulation functions in combination with form field or annotation updates; unexpected output files from redaction/encryption workflows that retain sensitive content.
  • Logs: Foxit application logs showing JavaScript execution events immediately preceding or following redaction or encryption operations on sensitive documents.
  • Process: Foxit PDF Editor or Reader processes executing JavaScript during print or redaction workflows on documents received from untrusted external sources.

Mitigation and workarounds

Foxit has released patches addressing this vulnerability; users should upgrade Foxit PDF Editor and PDF Reader to versions later than 2025.3.0.35737 (Foxit Security Bulletins). As a workaround, organizations should consider disabling PDF JavaScript execution in Foxit application settings (Edit > Preferences > JavaScript > uncheck "Enable JavaScript Actions") if JavaScript is not required for business operations. Additionally, implement manual review procedures to verify that redactions and encryption are correctly applied before distributing sensitive documents, and restrict opening PDFs from untrusted sources in environments handling sensitive data.

Additional resources


SourceThis report was generated using AI

Related Foxit PDF Reader vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-57260HIGH7.8
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57256HIGH7.8
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57259MEDIUM6.5
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57258MEDIUM6.1
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026
CVE-2026-57257MEDIUM6.1
  • Foxit PDF Reader logoFoxit PDF Reader
  • cpe:2.3:a:foxit:pdf_reader
NoYesJul 08, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management