CVE-2026-4947 Details
Description
Addressed a potential insecure direct object reference (IDOR) vulnerability in the signing invitation acceptance process. Under certain conditions, this issue could have allowed an attacker to access or modify unauthorized resources by manipulating user-supplied object identifiers, potentially leading to forged signatures and compromising the integrity and authenticity of documents undergoing the signing process. The issue was caused by insufficient authorization validation on referenced resources during request processing.
A vulnerability allowing insecure direct object reference (IDOR) has been identified in the signing invitation acceptance process of Foxit PDF Reader, Foxit PDF Editor, and Foxit eSign. This vulnerability arises from insufficient authorization validation on user-supplied object identifiers, which could be manipulated to access or modify unauthorized resources. Under certain conditions, this could lead to forged signatures, compromising the integrity and authenticity of documents in the signing process.
Users can update to the latest versions of Foxit PDF Reader or Foxit PDF Editor. For Foxit PDF Reader, the updated version can be downloaded from the Foxit website or via the application's update feature. For Foxit PDF Editor, the latest version is also available on the Foxit website or through the application's update option. Foxit eSign has been automatically updated to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 1, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.foxit.com/support/security-bulletins.html | Foxit | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-284 | Improper Access Control | Foxit |
Affected Products
| Product | Versions |
|---|---|
| foxit esign | < 2026-03-26 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | Foxit |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Apr 27, 2026 | Initial Analysis | [email protected] |
| Apr 1, 2026 | New CVE Received | Foxit |