---
id: CVE-2026-18622
title: >-
  Foxit PDF Editor/Reader inconsistently alerts users when signature fields are
  abnormally modified, including alterations to appearance, coordinates, or
  field duplication
summary: >-
  Foxit PDF Editor/Reader inconsistently alerts users when signature fields are
  abnormally modified, including alterations to appearance, coordinates, or
  field duplication. This may mislead users into trusting tampered documents,
  since the…
severity: medium
cvss: 4.7
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N'
cwe:
  - CWE-451
vendor: foxit
product: pdf_editor
affected:
  - pdf_editor <= 13.2.5.24109
  - 'pdf_editor >= 14.0.0.33046, <= 14.0.5.33580'
  - 'pdf_editor >= 2023.1.0.15510, <= 2023.3.0.23028'
  - 'pdf_editor >= 2024.1.0.23997, <= 2024.4.1.27687'
  - 'pdf_editor >= 2025.1.0.27937, <= 2025.3.0.35737'
  - 'pdf_editor >= 2026.1.0.36452, <= 2026.1.2.36540'
  - pdf_reader <= 2026.1.2.36540
  - pdf_editor <= 13.2.5.63482
  - 'pdf_editor >= 14.0.0.68868, <= 14.0.5.69339'
  - 'pdf_editor >= 2023.1.0.55583, <= 2023.3.0.63083'
  - 'pdf_editor >= 2024.1.0.63682, <= 2024.4.1.66479'
  - 'pdf_editor >= 2025.1.0.66692, <= 2025.3.0.69570'
  - 'pdf_editor >= 2026.1.0.70169, <= 2026.1.2.70304'
  - pdf_reader <= 2026.1.2.70304
published: '2026-08-13'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T17:00:11.150'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-18622'
references:
  - url: 'https://www.foxit.com/support/security-bulletins.html'
    label: 14984358-7092-470d-8f34-ade47a7658a2
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-08-13T14:15:06.149870Z'
ingestedAt: '2026-09-13T14:45:10.846Z'
epss: 0.00123
epssPercentile: 0.01788
---

## Overview

Foxit PDF Editor/Reader inconsistently alerts users when signature fields are abnormally modified, including alterations to appearance, coordinates, or field duplication. This may mislead users into trusting tampered documents, since the UI cannot accurately reflect the actual integrity status of signatures.

## Affected

- `pdf_editor <= 13.2.5.24109`
- `pdf_editor >= 14.0.0.33046, <= 14.0.5.33580`
- `pdf_editor >= 2023.1.0.15510, <= 2023.3.0.23028`
- `pdf_editor >= 2024.1.0.23997, <= 2024.4.1.27687`
- `pdf_editor >= 2025.1.0.27937, <= 2025.3.0.35737`
- `pdf_editor >= 2026.1.0.36452, <= 2026.1.2.36540`
- `pdf_reader <= 2026.1.2.36540`
- `pdf_editor <= 13.2.5.63482`
- `pdf_editor >= 14.0.0.68868, <= 14.0.5.69339`
- `pdf_editor >= 2023.1.0.55583, <= 2023.3.0.63083`
- `pdf_editor >= 2024.1.0.63682, <= 2024.4.1.66479`
- `pdf_editor >= 2025.1.0.66692, <= 2025.3.0.69570`
- `pdf_editor >= 2026.1.0.70169, <= 2026.1.2.70304`
- `pdf_reader <= 2026.1.2.70304`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
