{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-18622","assignerOrgId":"14984358-7092-470d-8f34-ade47a7658a2","state":"PUBLISHED","assignerShortName":"Foxit","dateReserved":"2026-08-03T08:05:24.886Z","datePublished":"2026-08-13T07:00:23.071Z","dateUpdated":"2026-08-13T14:15:16.968Z"},"containers":{"cna":{"providerMetadata":{"orgId":"14984358-7092-470d-8f34-ade47a7658a2","shortName":"Foxit","dateUpdated":"2026-08-13T07:00:23.071Z"},"title":"Foxit PDF Editor/Reader's signature-validation pop-up reports modified certified documents as valid","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-451","description":"CWE-451: User Interface (UI) Misrepresentation of Critical Information","type":"CWE"}]}],"impacts":[{"capecId":"CAPEC-148","descriptions":[{"lang":"en","value":"CAPEC-148: Content Spoofing"}]}],"affected":[{"vendor":"Foxit Software Inc.","product":"Foxit PDF Editor","platforms":["Windows","MacOS"],"versions":[{"status":"affected","version":"Versions 2026.1.2 and earlier"},{"status":"affected","version":"Versions 14.0.5 and earlier"},{"status":"affected","version":"Versions 13.2.5 and earlier"}],"defaultStatus":"unaffected"},{"vendor":"Foxit Software Inc.","product":"Foxit PDF Reader","platforms":["Windows","MacOS"],"versions":[{"status":"affected","version":"Versions 2026.1.2 and earlier"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"Foxit PDF Editor/Reader inconsistently alerts users when signature fields are abnormally modified, including alterations to appearance, coordinates, or field duplication. This may mislead users into trusting tampered documents, since the UI cannot accurately reflect the actual integrity status of signatures.","supportingMedia":[{"type":"text/html","base64":false,"value":"Foxit PDF Editor/Reader inconsistently alerts users when signature fields are abnormally modified, including alterations to appearance, coordinates, or field duplication. This may mislead users into trusting tampered documents, since the UI cannot accurately reflect the actual integrity status of signatures."}]}],"references":[{"url":"https://www.foxit.com/support/security-bulletins.html"}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV3_1":{"version":"3.1","attackVector":"LOCAL","attackComplexity":"HIGH","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"NONE","integrityImpact":"HIGH","availabilityImpact":"NONE","baseSeverity":"MEDIUM","baseScore":4.7,"vectorString":"CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N"}}],"credits":[{"lang":"en","value":"Enzo da Rosa Brum, Frederico Schardong, and Ricardo Felipe Custódio, all of the Computer Security Laboratory (LabSEC), Federal University of Santa Catarina (UFSC), Brazil","type":"finder"}],"source":{"discovery":"UNKNOWN"},"x_generator":{"engine":"Vulnogram 1.0.4"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-08-13T14:15:06.149870Z","id":"CVE-2026-18622","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-08-13T14:15:16.968Z"}}]}}