Foxit PDF Editor/Reader's signature-validation pop-up reports modified certified documents as valid
Summary
| CVE | CVE-2026-18622 |
|---|---|
| State | PUBLISHED |
| Assigner | Foxit |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-13 07:17:06 UTC |
| Updated | 2026-08-13 15:19:35 UTC |
| Description | Foxit PDF Editor/Reader inconsistently alerts users when signature fields are abnormally modified, including alterations to appearance, coordinates, or field duplication. This may mislead users into trusting tampered documents, since the UI cannot accurately reflect the actual integrity status of signatures. |
Risk And Classification
Primary CVSS: v3.1 4.7 MEDIUM from 14984358-7092-470d-8f34-ade47a7658a2
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
EPSS: 0.001220000 probability, percentile 0.023940000 (date 2026-08-14)
Problem Types: CWE-451 | CWE-451 CWE-451: User Interface (UI) Misrepresentation of Critical Information
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | 14984358-7092-470d-8f34-ade47a7658a2 | Secondary | 4.7 | MEDIUM | CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N |
| 3.1 | CNA | CVSS | 4.7 | MEDIUM | CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N |
CVSS v3.1 Breakdown
Attack Vector
LocalAttack Complexity
HighPrivileges Required
NoneUser Interaction
RequiredScope
UnchangedConfidentiality
NoneIntegrity
HighAvailability
NoneCVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Foxit Software Inc. | Foxit PDF Editor | affected Versions 2026.1.2 and earlier | Windows, MacOS |
| CNA | Foxit Software Inc. | Foxit PDF Editor | affected Versions 14.0.5 and earlier | Windows, MacOS |
| CNA | Foxit Software Inc. | Foxit PDF Editor | affected Versions 13.2.5 and earlier | Windows, MacOS |
| CNA | Foxit Software Inc. | Foxit PDF Reader | affected Versions 2026.1.2 and earlier | Windows, MacOS |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| www.foxit.com/support/security-bulletins.html | 14984358-7092-470d-8f34-ade47a7658a2 | www.foxit.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
Vendor Comments And Credit
Discovery Credit
CNA: Enzo da Rosa Brum, Frederico Schardong, and Ricardo Felipe Custódio, all of the Computer Security Laboratory (LabSEC), Federal University of Santa Catarina (UFSC), Brazil (en)
There are currently no legacy QID mappings associated with this CVE.