CVE-2026-91814
Received Received - Intake

Signature Validation Bypass in Foxit PDF Editor

Vulnerability report for CVE-2026-91814, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-23

Last updated on: 2026-09-23

Assigner: Foxit

Description

A signature validation vulnerability exists in Foxit PDF Editor/Reader’s handling of incrementally updated PDF documents. Changes to visible document content may not invalidate the existing signature, allowing attackers to alter signed content and potentially carry out content spoofing while the document continues to appear validly signed.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-23
Last Modified
2026-09-23
Generated
2026-09-23
AI Q&A
2026-09-23
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
foxit pdf_editor_reader *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-347 The product does not verify, or incorrectly verifies, the cryptographic signature for data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability involves a flaw in Foxit PDF Editor/Reader where changes to a signed PDF document do not invalidate the existing signature. Attackers can modify visible content in the document while keeping the signature appear valid, enabling content spoofing.

Impact Analysis

Attackers could alter signed documents to display false information while maintaining a valid signature. This could lead to misinformation, fraud, or unauthorized changes in documents you rely on, such as contracts or reports.

Compliance Impact

This vulnerability may compromise the integrity of signed documents, which could violate compliance requirements for data integrity and authenticity in regulations like GDPR and HIPAA. Organizations using Foxit PDF Editor/Reader may fail to meet these standards due to the risk of undetected document tampering.

Mitigation Strategies

Disable incremental updates in Foxit PDF Editor/Reader settings to prevent signature validation bypass. Avoid opening PDFs from untrusted sources until a patch is applied. Monitor Foxit's official updates for security fixes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-91814. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart