Sceawere

Vulnerability Detail

CVE-2026-18622UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Foxit PDF Editor Signature UI Inconsistency

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.7
Creation Date
4h ago
Vendor
Foxit Software Inc.
Product
Foxit PDF Editor
Attack Type
CWE-451: User Interface (UI) Misrepresentation of Critical Information
Vector String
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
Attack Complexity
HIGH

Narrative and Response

Description

Foxit PDF Editor/Reader inconsistently alerts users when signature fields are abnormally modified, including alterations to appearance, coordinates, or field duplication. This may mislead users into trusting tampered documents, since the UI cannot accurately reflect the actual integrity status of signatures.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.7",
  "pubDate": "2026-08-13T07:17:06.763Z",
  "pubdate": "2026-08-13T07:17:06.763Z",
  "executiveSummary": "An input validation and user interface integrity vulnerability exists within Foxit PDF Editor and Foxit PDF Reader related to digital signature validation and rendering.\nThe vulnerability manifests as inconsistent alerting mechanisms when cryptographic signature fields undergo abnormal post-signing modifications, specifically concerning alterations to visual appearance, coordinate positioning, or unauthorized field duplication.\nThe primary impact of this flaw is user deception, where the application's graphical user interface fails to accurately reflect the true cryptographic integrity status of a signed document.\nAffected systems include Foxit PDF Editor and Foxit PDF Reader across unspecified versions that process manipulated PDF structures.\nThe risk implications involve social engineering and targeted fraud, as victims may be misled into falsely trusting tampered documents bearing visually valid but fundamentally compromised digital signatures.\nAttacker capabilities require the ability to craft or modify Portable Document Format (PDF) files containing digital signatures, manipulating internal dictionary entries, object streams, or annotation parameters.\nNo specific authentication or network exposure requirements are inherently mandated for the core flaw, as exploitation relies on the victim opening a maliciously crafted PDF document locally within the vulnerable software.",
  "technicalDetails": "The root cause of the vulnerability stems from inadequate synchronization between the core cryptographic signature verification engine and the document rendering pipeline within Foxit PDF Editor and Foxit PDF Reader.\nWhen a PDF document is digitally signed, cryptographic hashes are computed over specific byte ranges of the file, binding the signature to the exact document state at the time of signing.\nStandard PDF specifications allow for incremental updates, but alterations to critical structural elements—such as signature field coordinates, widget annotations determining visual appearance, or the duplication of signature dictionary objects—should invalidate the signature state or trigger explicit, unambiguous security warnings to the end user.\nIn the context of this vulnerability, the parsing and rendering components fail to correctly evaluate these boundary conditions or suppress appropriate warning dialogs when discrepancies arise between the signed byte range and the modified visual representation.\nThe step-by-step attack flow proceeds as follows: First, an attacker acquires a legitimately signed PDF document or generates a signed baseline file. Second, the attacker utilizes programmatic PDF manipulation tools or scripts to alter the coordinates of the signature widget annotation, modify its visual appearance stream, or duplicate the signature field structures within an incremental update or the primary document catalog.\nThird, the attacker distributes the modified PDF document to the target victim. Fourth, when the victim opens the document using Foxit PDF Editor or Foxit PDF Reader, the application processes the tampered structure. Fifth, due to the inconsistent handling of the signature field metadata and rendering parameters, the user interface fails to display a critical integrity warning or incorrectly renders the signature as valid.\nConsequently, the victim is presented with a deceptive visual indicator of document integrity, masking the underlying tampering and facilitating successful social engineering or fraudulent operations.\nThe vulnerable component resides in the PDF parsing, signature verification, and user interface notification modules responsible for displaying signature status panels and warning dialogs."
}
CVE-2026-18622: Foxit PDF Editor Signature UI Inconsistency (MEDIUM Severity, CVSS: 4.7) - Sceawere