Security Advisory

CVE-2026-13129

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-07-08 07:36:30
Last updated 2026-07-08 13:20:30
Assigner Foxit
CVSS score 7.8
State PUBLISHED

Description

When the application opens a PDF file, JavaScript uses the damaged field tree to trigger field traversal, resulting in the program holding an invalid form object when accessing the field property path. Eventually, the application crashes due to reading an invalid pointer.