Junglewise Threat Intelligence

CVE-2026-91814: Foxit PDF Editor and Reader signature validation bypass in incremental updates

CVE-2026-91814 · Severity: medium · CVSS 5.3 · Published 2026-09-23

Technologies: Foxit PDF Reader, Foxit PDF Editor. Vendors: Foxit.

Executive brief

Foxit PDF Editor and Reader fail to properly validate digital signatures when PDF documents are incrementally updated. An attacker can modify the visible content of a signed PDF—such as text, images, or other elements—and the document will still appear to have a valid signature, enabling content spoofing and fraud. This affects the integrity of digitally signed documents used for contracts, agreements, and other critical business records.

Technical details

The vulnerability exists in the signature validation logic for incrementally updated PDF documents, where changes to visible document content do not trigger signature invalidation. An attacker with the ability to modify a PDF file can alter visible content while the original signature remains valid, exploiting a failure to detect modifications in incremental updates. This is a signature validation bypass that does not require authentication or network access, only the ability to supply a modified PDF file to a user.

Affected products

  • Foxit PDF Reader 2026.2.0.39747 and earlier
  • Foxit PDF Editor 2026.2.0.39747 and all previous 2026.x versions, 2025.3.0.35737 and all previous 2025.x versions, 2024.4.1.27687 and all previous 2024.x versions, 2023.3.0.23028 and all previous 2023.x versions, 14.0.7.33751 and all previous 14.x versions, 13.2.6.24111 and earlier

Timeline

  • 2026-09-23: disclosed
  • 2026-09-23: patched: Updates available in Foxit PDF Reader 2026.2.1 and Foxit PDF Editor 2026.2.1/14.0.8

References

Related threats