Signature Validation Vulnerability in Foxit PDF Editor/Reader
CVE-2026-91814

5.3MEDIUM

Key Information:

Vendor

Foxit Inc.

Vendor
CVE Published:
23 September 2026

What is CVE-2026-91814?

A vulnerability has been identified in Foxit PDF Editor/Reader that relates to its handling of incrementally updated PDF documents. This flaw allows alterations to signed content without invalidating the signature, leading to potential content spoofing. Attackers could exploit this weakness to manipulate visible content of a document while it retains the appearance of a valid signature, posing significant risks to document integrity.

Affected Version(s)

Foxit PDF Editor Windows Versions 2026.2 and earlier

Foxit PDF Editor Windows Versions 14.0.7 and earlier

Foxit PDF Editor Windows Versions 13.2.6 and earlier

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jan Slabon (Setasign GmbH & Co. KG), Germany
.