Signature Integrity Flaw in Foxit PDF Editor/Reader
CVE-2026-18622
4.7MEDIUM
What is CVE-2026-18622?
Foxit PDF Editor/Reader has a vulnerability that fails to consistently notify users about unauthorized modifications in signature fields. This includes potential alterations to the appearance, coordinates, or duplication of fields. Such inconsistencies in alerts could lead users to mistakenly trust documents that have been tampered with, as the user interface may not accurately display the actual integrity status of the signatures.
Affected Version(s)
Foxit PDF Editor Windows Versions 2026.1.2 and earlier
Foxit PDF Editor Windows Versions 14.0.5 and earlier
Foxit PDF Editor Windows Versions 13.2.5 and earlier
References
CVSS V3.1
Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Enzo da Rosa Brum, Frederico Schardong, and Ricardo Felipe CustĂłdio, all of the Computer Security Laboratory (LabSEC), Federal University of Santa Catarina (UFSC), Brazil
