rootpwn

medium · CVSS v3 5.3 · EPSS 0.00172

CVE-2026-91814

Foxit PDF Editor/Reader fails to invalidate signatures when documents are incrementally updated, allowing content changes to go unnoticed. T

Overview

Foxit PDF Editor/Reader fails to invalidate signatures when documents are incrementally updated, allowing content changes to go unnoticed. The flaw can lead to spoofed documents that still appear signed. It matters because many organizations rely on PDF signatures for legal and compliance purposes.

Description

A signature validation vulnerability exists in Foxit PDF Editor/Reader’s handling of incrementally updated PDF documents. Changes to visible document content may not invalidate the existing signature, allowing attackers to alter signed content and potentially carry out content spoofing while the document continues to appear validly signed.

Impact

Confidentiality: attackers can modify signed documents, undermining trust. Integrity: signatures may no longer reflect true content. Availability: no direct impact. Defenders must treat altered PDFs as untrusted and verify signatures against original content.

Remediation

Apply the latest Foxit security patch or upgrade to the newest version. Disable incremental PDF updates if possible. Use external PDF validation tools that check signature against full document hash. Monitor for anomalous PDFs and enforce strict signature verification policies.

Risk context

The CVSS score of 5.3 indicates medium risk, and the EPSS of 0.00172 suggests low likelihood of exploitation. Nonetheless, the potential for legal and compliance breaches warrants prompt patching.

Affected products

  • Foxit PDF Editor
  • Foxit PDF Reader

Scores

Severity
medium
CVSS v2
5.4
CVSS v3
5.3
CVSS v4
EPSS
0.00172

PDF signature Foxit content-spoofing document-validation

← All CVEs