CVE-2026-3774 Details
Description
The application allows PDF JavaScript and document/print actions (such as WillPrint/DidPrint) to update form fields, annotations, or optional content groups (OCGs) immediately before or after redaction, encryption, or printing. These script‑driven updates are not fully covered by the existing redaction, encryption, and printing logic, which, under specific document structures and user workflows, may cause a small amount of sensitive content to remain unremoved or unencrypted as expected, or result in printed output that slightly differs from what was reviewed on screen.
A vulnerability exists in Foxit PDF Reader and Foxit PDF Editor that allows PDF JavaScript and document/print actions to modify form fields, annotations, or optional content groups just before or after redaction, encryption, or printing. This issue arises because the application's current redaction, encryption, and printing processes do not fully account for these script-driven updates. Under certain document structures and user workflows, this oversight may leave some sensitive content unremoved or unencrypted, or cause printed materials to differ slightly from what was displayed on screen. The vulnerability affects Foxit PDF Reader for Windows versions through 2025.3.0.35737, Foxit PDF Editor for Windows versions 2025.3.0.35737 and earlier, as well as all previous 2025.x versions, 2024.x versions prior to 2024.4.1.27687, 2023.x versions prior to 2023.3.0.23028, 14.x versions prior to 14.0.2.33402, and 13.2.2.24014 and earlier. Foxit PDF Editor for Mac versions 2025.3.0.69570 and all previous 2025.x versions, 2024.4.1.66479 and all previous 2024.x versions, 2023.3.0.63083 and all previous 2023.x versions, 14.0.2.69164 and all previous 14.x versions, and 13.2.2.63349 and earlier are also affected.
Users can update to Foxit PDF Reader or Foxit PDF Editor version 2026.1 or later. Instructions for updating are available on the Foxit website.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.foxit.com/support/security-bulletins.html | Foxit | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-200 | Exposure of Sensitive Information to an Unauthorized Actor | Foxit |
Affected Products
| Product | Versions |
|---|---|
| foxit pdf editor | <= 13.2.2.24014 >= 14.0.0.33046, <= 14.0.2.33402 >= 2023.1.0.15510, <= 2023.3.0.23028 >= 2024.1.0.23997, <= 2024.4.1.27687 >= 2025.1.0.27937, <= 2025.3.0.35737 |
CPE
Remediation
| |
| foxit pdf reader | <= 2025.3.0.35737 |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Foxit |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 10, 2026 | Initial Analysis | [email protected] |
| Apr 1, 2026 | New CVE Received | Foxit |