Signature Integrity Flaw in Foxit PDF Editor/Reader
CVE-2026-18622

4.7MEDIUM

Key Information:

Vendor

Foxit Inc.

Vendor
CVE Published:
13 August 2026

What is CVE-2026-18622?

Foxit PDF Editor/Reader has a vulnerability that fails to consistently notify users about unauthorized modifications in signature fields. This includes potential alterations to the appearance, coordinates, or duplication of fields. Such inconsistencies in alerts could lead users to mistakenly trust documents that have been tampered with, as the user interface may not accurately display the actual integrity status of the signatures.

Affected Version(s)

Foxit PDF Editor Windows Versions 2026.1.2 and earlier

Foxit PDF Editor Windows Versions 14.0.5 and earlier

Foxit PDF Editor Windows Versions 13.2.5 and earlier

References

CVSS V3.1

Score:
4.7
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Enzo da Rosa Brum, Frederico Schardong, and Ricardo Felipe CustĂłdio, all of the Computer Security Laboratory (LabSEC), Federal University of Santa Catarina (UFSC), Brazil
.