CVE-2026-18622
4.7
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
Summary
Foxit PDF Editor/Reader inconsistently alerts users when signature fields are abnormally modified, including alterations to appearance, coordinates, or field duplication. This may mislead users into trusting tampered documents, since the UI cannot accurately reflect the actual integrity status of signatures.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Foxit Software Inc. | Foxit PDF Editor | Versions 2026.1.2 and earlier | affected |
| Foxit Software Inc. | Foxit PDF Editor | Versions 14.0.5 and earlier | affected |
| Foxit Software Inc. | Foxit PDF Editor | Versions 13.2.5 and earlier | affected |
| Foxit Software Inc. | Foxit PDF Reader | Versions 2026.1.2 and earlier | affected |
Weaknesses
- CWE-451: CWE-451: User Interface (UI) Misrepresentation of Critical Information
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.