4.7
CVE-2026-18622
- EPSS 0.12%
- Veröffentlicht 13.08.2026 07:00:23
- Zuletzt bearbeitet 13.08.2026 15:19:35
- CVE-Watchlists
- Unerledigt
Foxit PDF Editor/Reader's signature-validation pop-up reports modified certified documents as valid
Foxit PDF Editor/Reader inconsistently alerts users when signature fields are abnormally modified, including alterations to appearance, coordinates, or field duplication. This may mislead users into trusting tampered documents, since the UI cannot accurately reflect the actual integrity status of signatures.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerFoxit Software Inc.
≫
Produkt
Foxit PDF Editor
Default Statusunaffected
Version
Versions 2026.1.2 and earlier
Status
affected
Version
Versions 14.0.5 and earlier
Status
affected
Version
Versions 13.2.5 and earlier
Status
affected
HerstellerFoxit Software Inc.
≫
Produkt
Foxit PDF Reader
Default Statusunaffected
Version
Versions 2026.1.2 and earlier
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.12% | 0.024 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| 14984358-7092-470d-8f34-ade47a7658a2 | 4.7 | 1 | 3.6 |
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
|
CWE-451 User Interface (UI) Misrepresentation of Critical Information
The user interface (UI) does not properly represent critical information to the user, allowing the information - or its source - to be obscured or spoofed. This is often a component in phishing attacks.
https://www.foxit.com/support/security-bulletins.html