Description
Foxit PDF Editor/Reader inconsistently alerts users when signature fields are abnormally modified, including alterations to appearance, coordinates, or field duplication. This may mislead users into trusting tampered documents, since the UI cannot accurately reflect the actual integrity status of signatures.
Published: 2026-08-13
Score: 4.7 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Signature validity misrepresentation
Action: Assess Impact
AI Analysis

Impact

Foxit PDF Editor/Reader displays an inconsistent popup when a signature field is altered in appearance, placement, or duplication. Because the user interface does not accurately reflect the real integrity state of the signature, a user may mistakenly believe that a tampered document remains trusted. The flaw does not grant code execution or direct system compromise but can lead to the acceptance of altered or fraudulent documents, potentially exposing the user to misinformation, data tampering, or business process disruption.

Affected Systems

Foxit Software Inc.’s PDF Editor and PDF Reader applications are affected. Specific version information is not provided, so all released versions should be treated as potentially vulnerable until a patch is issued.

Risk and Exploitability

The CVSS score of 4.7 indicates moderate severity. No EPSS score is available, and the vulnerability is not listed in the CISA KEV catalog at this time. Based on the description, the likely attack vector is a user opening a malicious PDF; the attacker would modify signature fields to appear valid, exploiting the UI’s inconsistent alerting. The vulnerability requires no special privileges beyond user interaction with the document, making it relatively accessible to malicious actors who can target end users with deceptive PDFs.

Generated by OpenCVE AI on August 13, 2026 at 08:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Foxit PDF Editor and Reader to the latest version as soon as a vendor patch is released.
  • Disable or ignore signature validation pop‑ups and verify signatures using a trusted external verification tool.
  • Configure document security settings to warn or block modified signature fields, or use a higher‑assurance PDF reader that displays accurate signature status.

Generated by OpenCVE AI on August 13, 2026 at 08:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Apple
Apple macos
Foxit
Foxit pdf Editor
Foxit pdf Reader
Microsoft
Microsoft windows
CPEs cpe:2.3:a:foxit:pdf_editor:*:*:*:*:*:*:*:*
cpe:2.3:a:foxit:pdf_reader:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
Vendors & Products Apple
Apple macos
Foxit
Foxit pdf Editor
Foxit pdf Reader
Microsoft
Microsoft windows

Thu, 13 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 13 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Foxitsoftware
Foxitsoftware foxit Pdf Editor
Foxitsoftware foxit Reader
Vendors & Products Foxitsoftware
Foxitsoftware foxit Pdf Editor
Foxitsoftware foxit Reader

Thu, 13 Aug 2026 07:15:00 +0000

Type Values Removed Values Added
Description Foxit PDF Editor/Reader inconsistently alerts users when signature fields are abnormally modified, including alterations to appearance, coordinates, or field duplication. This may mislead users into trusting tampered documents, since the UI cannot accurately reflect the actual integrity status of signatures.
Title Foxit PDF Editor/Reader's signature-validation pop-up reports modified certified documents as valid
Weaknesses CWE-451
References
Metrics cvssV3_1

{'score': 4.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N'}


Subscriptions

Apple Macos
Foxit Pdf Editor Pdf Reader
Foxitsoftware Foxit Pdf Editor Foxit Reader
Microsoft Windows
cve-icon MITRE

Status: PUBLISHED

Assigner: Foxit

Published:

Updated: 2026-08-13T14:15:16.968Z

Reserved: 2026-08-03T08:05:24.886Z

Link: CVE-2026-18622

cve-icon Vulnrichment

Updated: 2026-08-13T14:15:13.099Z

cve-icon NVD

Status : Analyzed

Published: 2026-08-13T07:17:06.763

Modified: 2026-09-10T17:00:11.150

Link: CVE-2026-18622

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T10:15:07Z

Weaknesses
  • CWE-451

    User Interface (UI) Misrepresentation of Critical Information