CVE-2026-91814 Overview
CVE-2026-91814 is a signature validation vulnerability in Foxit PDF Editor and Foxit PDF Reader. The flaw affects how the applications process incrementally updated PDF documents. Changes to visible document content may not invalidate an existing digital signature. Attackers can alter signed content while the document continues to display as validly signed. This enables content spoofing against users who trust the signature indicator. The vulnerability is tracked under CWE-347: Improper Verification of Cryptographic Signature.
Critical Impact
Attackers can modify visible content in signed PDFs without invalidating the signature, undermining document integrity and enabling forgery of contracts, invoices, and other trust-critical documents.
Affected Products
- Foxit PDF Editor
- Foxit PDF Reader
- Specific version details are published in the Foxit Security Bulletins
Discovery Timeline
- 2026-09-23 - CVE-2026-91814 published to the National Vulnerability Database (NVD)
- 2026-09-23 - Last updated in NVD database
Technical Details for CVE-2026-91814
Vulnerability Analysis
The vulnerability resides in the signature validation logic that processes PDF documents modified through incremental updates. PDF supports appending new revisions to a file without rewriting the original bytes. A properly implemented validator must confirm that any content covered by an existing signature remains unchanged in later revisions. Foxit PDF Editor and Reader fail to perform this check consistently. As a result, an attacker can append an incremental update that overlays or replaces visible content while the signature verification routine still reports the document as valid.
This class of flaw is commonly referred to as an incremental saving attack or a shadow attack. The signature cryptography itself remains intact. The failure is in the application logic that decides whether post-signature modifications alter signed content. Users who rely on the signature indicator to verify document authenticity will see valid signature status on a document whose visible contents have been changed.
Root Cause
The root cause is improper verification of a cryptographic signature covering all rendered content after incremental updates. The validator does not fully compare the byte ranges signed by the original signature against the rendered content produced from the latest revision. Objects added or overridden in the update section can change what the user sees without breaking signature verification.
Attack Vector
Exploitation requires network delivery of a malicious PDF and user interaction to open the file in a vulnerable Foxit product. The attacker starts with a legitimately signed PDF, appends an incremental update that modifies visible objects such as text, form fields, or annotations, and delivers the modified file to a target. The recipient opens the file in Foxit PDF Editor or Reader, sees a valid signature indicator, and trusts the altered content.
No verified public exploit code is available. Technical details are described in prose based on the vendor advisory. See the Foxit Security Bulletins for vendor-authored technical information.
Detection Methods for CVE-2026-91814
Indicators of Compromise
- PDF files containing multiple %%EOF markers indicating incremental updates applied after the original signed revision
- Signed PDF documents where the byte range declared in the signature dictionary does not cover the entire file
- Emails or file-sharing events delivering signed PDFs from senders whose signing certificate does not match the displayed content context
Detection Strategies
- Parse inbound PDFs at the mail gateway and flag signed documents whose signature ByteRange excludes trailing content
- Cross-validate signed PDFs using a second independent PDF validator and alert when validation results disagree
- Log Foxit PDF Editor and Reader process launches with associated file hashes to enable retrospective hunting when new IOCs surface
Monitoring Recommendations
- Monitor endpoint telemetry for Foxit application execution paired with PDFs received from external sources
- Track version telemetry for FoxitPDFReader.exe and FoxitPDFEditor.exe to identify hosts running unpatched builds
- Review document workflows that depend on signature validity, such as contract signing and invoice approval, for anomalies
How to Mitigate CVE-2026-91814
Immediate Actions Required
- Update Foxit PDF Editor and Foxit PDF Reader to the fixed versions listed in the Foxit Security Bulletins
- Inventory endpoints running Foxit products and prioritize patching for users who process signed PDFs in trust-sensitive workflows
- Instruct users to verify signed documents using a second validator when signature trust is business-critical
Patch Information
Foxit publishes fixed builds and version details in the Foxit Security Bulletins. Apply the vendor-supplied update for both Foxit PDF Editor and Foxit PDF Reader across all supported platforms.
Workarounds
- Route signed PDFs through a secondary validation tool that enforces full byte-range coverage before accepting the document
- Configure email and collaboration platforms to warn recipients when signed PDFs contain incremental updates
- Restrict the use of Foxit PDF Editor and Reader for signature-critical workflows until patches are applied
# Example: hunt for PDFs with multiple EOF markers on a file share
find /shared/documents -name "*.pdf" -print0 | \
xargs -0 -I{} sh -c 'count=$(grep -c "%%EOF" "{}"); \
[ "$count" -gt 1 ] && echo "$count EOFs: {}"'
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
