Description
Foxit PDF Editor/Reader inconsistently alerts users when signature fields are abnormally modified, including alterations to appearance, coordinates, or field duplication. This may mislead users into trusting tampered documents, since the UI cannot accurately reflect the actual integrity status of signatures.
Published: 2026-08-13
Score: 4.7 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Foxit PDF Editor/Reader displays an inconsistent popup when a signature field is altered in appearance, placement, or duplication. Because the user interface does not accurately reflect the real integrity state of the signature, a user may mistakenly believe that a tampered document remains trusted. The flaw does not grant code execution or direct system compromise but can lead to the acceptance of altered or fraudulent documents, potentially exposing the user to misinformation, data tampering, or business process disruption.

Affected Systems

Foxit Software Inc.’s PDF Editor and PDF Reader applications are affected. Specific version information is not provided, so all released versions should be treated as potentially vulnerable until a patch is issued.

Risk and Exploitability

The CVSS score of 4.7 indicates moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog at this time. Based on the description, the likely attack vector is a user opening a malicious PDF; the attacker would modify signature fields to appear valid, exploiting the UI’s inconsistent alerting. The vulnerability requires no special privileges beyond user interaction with the document, making it relatively accessible to malicious actors who can target end users with deceptive PDFs.

Generated by OpenCVE AI on August 13, 2026 at 08:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Foxit PDF Editor and Reader to the latest version as soon as a vendor patch is released.
  • Disable or ignore signature validation pop‑ups and verify signatures using a trusted external verification tool.
  • Configure document security settings to warn or block modified signature fields, or use a higher‑assurance PDF reader that displays accurate signature status.

Generated by OpenCVE AI on August 13, 2026 at 08:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Foxitsoftware
Foxitsoftware foxit Pdf Editor
Foxitsoftware foxit Reader
Vendors & Products Foxitsoftware
Foxitsoftware foxit Pdf Editor
Foxitsoftware foxit Reader

Thu, 13 Aug 2026 07:15:00 +0000

Type Values Removed Values Added
Description Foxit PDF Editor/Reader inconsistently alerts users when signature fields are abnormally modified, including alterations to appearance, coordinates, or field duplication. This may mislead users into trusting tampered documents, since the UI cannot accurately reflect the actual integrity status of signatures.
Title Foxit PDF Editor/Reader's signature-validation pop-up reports modified certified documents as valid
Weaknesses CWE-451
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N'}


Subscriptions

Foxitsoftware Foxit Pdf Editor Foxit Reader
cve-icon MITRE

Status: PUBLISHED

Assigner: Foxit

Published:

Updated: 2026-08-13T07:00:23.071Z

Reserved: 2026-08-03T08:05:24.886Z

Link: CVE-2026-18622

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-13T07:17:06.763

Modified: 2026-08-13T07:17:06.763

Link: CVE-2026-18622

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T10:15:07Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information