CVE-2026-18622
Foxit PDF Editor/Reader's signature-validation pop-up reports modified certified documents as valid
CVSS Score
4.7
EPSS Score
0.0%
EPSS Percentile
0th
Foxit PDF Editor/Reader inconsistently alerts users when signature fields are abnormally modified, including alterations to appearance, coordinates, or field duplication. This may mislead users into trusting tampered documents, since the UI cannot accurately reflect the actual integrity status of signatures.
| CWE | CWE-451 |
| Vendor | foxit software inc. |
| Product | foxit pdf editor |
| Published | Aug 13, 2026 |
Stay Ahead of the Next One
Get instant alerts for foxit software inc. foxit pdf editor
Be the first to know when new medium vulnerabilities affecting foxit software inc. foxit pdf editor are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N Attack Vector
Local
Attack Complexity
High
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
None
Integrity
High
Availability
None
Affected Versions
Foxit Software Inc. / Foxit PDF Editor
Versions 2026.1.2 and earlier Versions 14.0.5 and earlier Versions 13.2.5 and earlier
Foxit Software Inc. / Foxit PDF Reader
Versions 2026.1.2 and earlier
References
Credits
Enzo da Rosa Brum, Frederico Schardong, and Ricardo Felipe Custódio, all of the Computer Security Laboratory (LabSEC), Federal University of Santa Catarina (UFSC), Brazil