Signature Validation Vulnerability in Foxit PDF Editor/Reader
CVE-2026-91814
5.3MEDIUM
What is CVE-2026-91814?
A vulnerability has been identified in Foxit PDF Editor/Reader that relates to its handling of incrementally updated PDF documents. This flaw allows alterations to signed content without invalidating the signature, leading to potential content spoofing. Attackers could exploit this weakness to manipulate visible content of a document while it retains the appearance of a valid signature, posing significant risks to document integrity.
Affected Version(s)
Foxit PDF Editor Windows Versions 2026.2 and earlier
Foxit PDF Editor Windows Versions 14.0.7 and earlier
Foxit PDF Editor Windows Versions 13.2.6 and earlier
References
CVSS V3.1
Score:
5.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Jan Slabon (Setasign GmbH & Co. KG), Germany
