CVE-2026-18622
Low
No strong exploitation signal.
CVSS base
4.7
MEDIUM
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
EPSS — probability of exploitation (30 days)
0.1%
2.4th percentile
CISA KEV
Not listed
Weakness / dates
CWE-451
Published 2026-08-13 · modified 2026-09-10
CVSS breakdown
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:H/A:N
| Attack Vector | L | Local |
| Attack Complexity | H | High |
| Privileges Required | N | None |
| User Interaction | R | Required |
| Scope | U | Unchanged |
| Confidentiality | N | None |
| Integrity | H | High |
| Availability | N | None |
Timeline
- 2026-08-13 — Published (NVD)
- 2026-09-10 — Last modified (NVD)
Description
Foxit PDF Editor/Reader inconsistently alerts users when signature fields are abnormally modified, including alterations to appearance, coordinates, or field duplication. This may mislead users into trusting tampered documents, since the UI cannot accurately reflect the actual integrity status of signatures.