AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-18597

HIGH · CVSS 8.5 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-08-06 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The PDF creation feature of Foxit PDF Services API is vulnerable to a Server-Side Request Forgery (SSRF) attack due to improper validation of URL redirection, allowing attackers to access sensitive information by referencing external files. This high-severity vulnerability poses a significant risk to organizations using the affected API, particularly those handling sensitive data. It is crucial for security teams and developers utilizing Foxit PDF Services to prioritize remediation efforts to mitigate potential information disclosure risks.

CVE
CVE-2026-18597
Severity
HIGH
CVSS
8.5
EPSS
0.18%

Original NVD Description

The PDF creation feature of Foxit PDF Services API supports referencing external files. Although local file access is restricted, an attacker could trigger an SSRF vulnerability by using URL redirection to bypass validation, leading to information disclosure.