CVE-2026-57239Disclosure(foxit / pdf_editor)

MEDIUMCVSS 7.8 · HIGH

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Patch foxit pdf_editor systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: High priority (within 72h)

NVD description

The user-controllable executable files will be directly executed by high-privilege processes, allowing low-privilege users to have the opportunity to elevate their privileges to NT AUTHORITY\SYSTEM.

4.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-427

Priority

MEDIUM

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • pdf_editor
  • pdf_reader
  • windows

Threat summary

  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 13 mentions across 7 observed days
  • Momentum state: stable

What's happening

  • Exploit tool or code specified in 4 signals
  • PoC mentioned or linked in 4 signals
  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 10 signals
  • Disclosure: 7 classified signals
  • Peaked 4d ago at 3 mentions (2026-07-20); latest day: 2
  • 13 total mentions across 7 days

Affected systems

Products
pdf_editorpdf_readerwindows

1 version affected across 3 products

Deep dive

Activity timeline13 mentions / 7d
01223Mentions · 2026-07-08: 2Mentions · 2026-07-09: 1Mentions · 2026-07-20: 3Mentions · 2026-07-23: 2Mentions · 2026-07-29: 2Mentions · 2026-08-03: 1Mentions · 2026-09-13: 2PoC Mentioned / Linked · 2026-07-23: 2PoC Mentioned / Linked · 2026-07-29: 2Exploit Tool / Code · 2026-07-23: 2Exploit Tool / Code · 2026-07-29: 2Patch / Workaround · 2026-07-09: 1Patch / Workaround · 2026-07-29: 2Technical Details · 2026-07-08: 2Technical Details · 2026-07-09: 1Technical Details · 2026-07-20: 1Technical Details · 2026-07-23: 1Technical Details · 2026-07-29: 2Technical Details · 2026-08-03: 1Technical Details · 2026-09-13: 207-0807-0907-2007-2307-2908-0309-13
Signal classification5 categories
Disclosure
753.8%
PoC
323.1%
Patch
17.7%
General
17.7%
Exploit
17.7%
Referenced assets10 URLs
Classification over time
DateTotalLabels
2026-07-082
Disclosure2
2026-07-091
Patch1
2026-07-203
Disclosure2General1
2026-07-232
PoC2
2026-07-292
Exploit1PoC1
2026-08-031
Disclosure1
2026-09-132
Disclosure2
Full discourse13 posts
  • Nicolas Krassas@Dinosn
    Disclosure

    Escalating All The Privileges With Foxit PDF Reader (CVE-2026–57239) https://blog.paradoxis.nl/escalating-all-the-privileges-with-foxit-pdf-reader-cve-2026-57239-582a78b60492

    Post summary

    The content references a newly disclosed privilege‑escalation flaw in Foxit PDF Reader (CVE‑2026‑57239) and links to a blog post for details, but provides no information on PoCs, exploitation, or patches.

    1331115489.0K
    160.9K followersView on X
  • ThreatWire@ThreatWire_
    PoC

    🚨 A public PoC has been released for CVE-2026-57239 affecting Foxit PDF Reader and Foxit PDF Editor The flaw allows a local privilege escalation (LPE) to NT AUTHORITY\SYSTEM via the applications update mechanism Patched in the latest releases 🔗 https://github.com/Paradoxis/CVE-2026-57239 #Foxit

    Post summary

    A public PoC for CVE-2026-57239 has been released, demonstrating local privilege escalation in Foxit PDF Reader/Editor, and the vulnerability is already patched in the latest releases.

    017091465.0K
    1.5K followersView on X
  • Daily CyberSecurity@Daily_CyberSec
    PoC

    A public proof-of-concept for CVE-2026-57239 turns a Foxit PDF Reader vulnerability into full SYSTEM privileges via local privilege escalation. #Foxit #CVE202657239 #PrivilegeEscalation #InfoSec http://securityonline.info/foxit-pdf-reader-cve-2026-57239/

    Post summary

    The post announces a public proof‑of‑concept for CVE‑2026‑57239, showing that a Foxit PDF Reader flaw can be leveraged for local privilege escalation to SYSTEM level, but it does not mention any patch or active exploitation.

    018059232.3K
    12.9K followersView on X
  • /r/netsec@_r_netsec
    Disclosure

    Escalating All The Privileges With Foxit PDF Reader (CVE-2026–57239) https://blog.paradoxis.nl/escalating-all-the-privileges-with-foxit-pdf-reader-cve-2026-57239-582a78b60492

    Post summary

    The text points to a blog post announcing a new privilege‑escalation vulnerability (CVE‑2026‑57239) in Foxit PDF Reader, providing technical details but no PoC, exploit, or patch information.

    010042193.8K
    34.1K followersView on X
  • /r/netsec@_r_netsec
    Disclosure

    Escalating All The Privileges With Foxit PDF Reader (CVE-2026–57239) https://blog.paradoxis.nl/escalating-all-the-privileges-with-foxit-pdf-reader-cve-2026-57239-582a78b60492

    Post summary

    The post announces a new privilege‑escalation flaw in Foxit PDF Reader (CVE‑2026‑57239) but does not provide a PoC, exploit code, technical details, or mitigation instructions.

    02015111.7K
    33.7K followersView on X
  • dbugs@ptdbugs
    Exploit

    CVE-2026-57239: Escalating All The Privileges With Foxit PDF Reader PT ID: PT-2026-56338 https://dbugs.ptsecurity.com/vulnerability/PT-2026-56338 Most local Windows LPEs require a complex exploitation chain. But sometimes all it takes is looking at how an application updates itself. Researcher Luke Paris (Paradoxis) discovered that the update mechanism of Foxit PDF Reader / PDF Editor allows a standard user to elevate privileges to "NT AUTHORITY\SYSTEM". The vulnerability was assigned the identifier CVE-2026-57239 -> (https://dbugs.ptsecurity.com/vulnerability/CVE-2026-57239). During update checks, the Foxit service, running with elevated privileges, downloaded and executed binaries whose paths could be controlled by an unprivileged user. As a result, a trusted process effectively executed arbitrary code with "SYSTEM" privileges. The vulnerability affects Foxit PDF Reader version 2026.1.1 and earlier, as well as several generations of Foxit PDF Editor (13.x, 14.x, 2023–2026). The fix was released as part of Foxit PDF Reader 2026.1.2 and the corresponding PDF Editor updates. Article: https://blog.paradoxis.nl/escalating-all-the-privileges-with-foxit-pdf-reader-cve-2026-57239-582a78b60492 PoC: https://github.com/Paradoxis/CVE-2026-57239 #dbugs_attacks

    Post summary

    Foxit PDF Reader’s update mechanism can be abused to gain SYSTEM privileges; a PoC was published and a patch released in 2026.1.2

    020101848
    3.5K followersView on X
  • moton@moton
    PoC

    CVE-2026-57239: Foxit PDF Reader SYSTEM Exploit PoC - https://securityonline.info/foxit-pdf-reader-cve-2026-57239/

    Post summary

    A Proof of Concept for CVE-2026-57239 in Foxit PDF Reader has been published, providing exploit code, but there is no evidence of active exploitation or available patches.

    01022121
    756 followersView on X
  • BBWriteup@bbwriteup
    General

    "Escalating All The Privileges With Foxit PDF Reader (CVE-2026–57239)" by Luke Paris #InfoSec #CyberSecurity #Hacking #BugBounty https://blog.paradoxis.nl/escalating-all-the-privileges-with-foxit-pdf-reader-cve-2026-57239-582a78b60492

    Post summary

    The post nominally announces a privilege‑escalation issue in Foxit PDF Reader (CVE‑2026‑57239) but provides no substantive technical, exploit, or mitigation information.

    00011136
    856 followersView on X
  • 浑水摸鱼@DavidJou734
    Disclosure

    https://blog.paradoxis.nl/escalating-all-the-privileges-with-foxit-pdf-reader-cve-2026-57239-582a78b60492 Escalating All The Privileges With Foxit PDF Reader (CVE-2026–57239)

    Post summary

    The linked blog post announces a new privilege‑escalation vulnerability in Foxit PDF Reader, identified as CVE-2026‑57239, but offers no evidence of active exploitation, a PoC, or mitigation.

    0001053
    67 followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    Foxit PDF Reader の権限昇格の脆弱性 CVE-2026-57239:SYSTEM 権限奪取の恐れ https://iototsecnews.jp/2026/07/24/foxit-pdf-reader-flaw-lets-local-attackers-gain-system-privileges-via-dll-sideloading/ Foxit PDF Reader の脆弱性 CVE-2026-57239 について解説する記事です。この件は、ローカル環境で権限昇格が発生してしまう問題です。主な原因は、特権で動作する更新サービスが、誰でも書き込める ProgramData ディレクトリ内のファイルを監視していた点にあります。悪意のユーザーが暗号化された更新リクエストを送信すると、通常ユーザーの AppData 内からアップデーターが呼び出されてしまいます。 さらに、その UI 上のリンク操作により、作業ディレクトリから外部ファイル "winspool.drv" が SYSTEM 権限で読み込まれてしまう、DLL サイド・ローディングの仕組みが重なったことで、権限の昇格につながってしまいます。ご利用のチームは、ご注意ください。 #CVE202657239 #Foxit #PDFReader #Vulnerability

    Post summary

    The article announces and explains the CVE‑2026‑57239 privilege‑escalation flaw in Foxit PDF Reader, detailing the DLL side‑loading mechanism, but provides no PoC, exploit code, patch information, or evidence of active exploitation.

    00000146
    504 followersView on X
  • Windows Forum@windowsforum
    Patch

    🚨 Foxit patch time: CVE-2026-57239 could turn update-service access into SYSTEM. “Just a PDF reader” is adorable until your attacker gets admin privileges through the update pipe. #Windows #Security #PatchNow https://windowsforum.com/threads/cve-2026-57239-update-foxit-to-2026-1-2-14-0-5-or-13-2-5.436444/?utm_source=x&utm_medium=social&utm_campaign=news_node4 #PdfReader #VulnerabilityManagement #PdfEditor https://t.co/hKlc3OiOwV

    Post summary

    The post highlights CVE‑2026‑57239 in Foxit as a privilege‑escalation flaw via the update service and urges users to apply patches or updates to mitigate the risk.

    0000068
    1.2K followersView on X
  • Infoflowcloud@infoflowcloud
    Disclosure

    🚨*CVE* CVE-2026-57239 The user-controllable executable files will be directly executed by high-privilege processes, allowing low-privilege users to have the opportunity to elevate their pr… https://www.cve.org/CVERecord?id=CVE-2026-57239 ----- Traducción: CVE-2026-57239 Los… http://infoflow.cloud`

    Post summary

    The tweet announces CVE-2026-57239, detailing a privilege escalation vulnerability where user‑controlled executables are run by elevated processes, and links to the official CVE record.

    0000035
    91 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-57239 The user-controllable executable files will be directly executed by high-privilege processes, allowing low-privilege users to have the opportunity to elevate their pr… https://www.cve.org/CVERecord?id=CVE-2026-57239

    Post summary

    The text announces CVE-2026-57239, describing a privilege‑elevation issue where user‑controlled executables can be run by high‑privilege processes, but it offers no PoC, exploit, or mitigation details.

    00000698
    57.8K followersView on X
CPE platform detail3 entries

3 of 3 entries

PartVendorProductVersionTarget SWTarget HW
Appfoxitpdf_editor---
Appfoxitpdf_reader---
OSmicrosoftwindows---

Explore more