← Vulnerability feed

Vulnerability record · CVE-2025-59802 · published 11 December 2025

CVE-2025-59802: Foxit pdf editor authentication bypass by spoofing vulnerability

Foxit · Pdf Editor

Foxit PDF Editor and Reader before 2025.2.1 allow signature spoofing via OCG. When Optional Content Groups (OCG) are supported, the state property of an OCG is runtime-only and not included in the digital signature computation buffer. An attacker can leverage JavaScript or PDF triggers to dynamically change the visibility of OCG content after signing (Post-Sign), allowing the visual content of a signed PDF to be modified without invalidating the signature. This may result in a mismatch between the signed content and what the signer or verifier sees, undermining the trustworthiness of the digital signature. The fixed versions are 2025.2.1, 14.0.1, and 13.2.1.

7.5 CVSS 3.1 High EPSS 0.32% · top 78.0% CWE-290 · Authentication bypass by spoofing
7.5CVSS 3.1 base score
0.32%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

Foxit PDF Editor and Reader before 2025.2.1 allow signature spoofing via OCG. When Optional Content Groups (OCG) are supported, the state property of an OCG is runtime-only and not included in the digital signature computation buffer. An attacker can leverage JavaScript or PDF triggers to dynamically change the visibility of OCG content after signing (Post-Sign), allowing the visual content of a signed PDF to be modified without invalidating the signature. This may result in a mismatch between the signed content and what the signer or verifier sees, undermining the trustworthiness of the digital signature. The fixed versions are 2025.2.1, 14.0.1, and 13.2.1.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2025-59802 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2022-28104Foxit pdf editor unrestricted file upload vulnerabilityFoxit PDF Editor v11.3.1 was discovered to contain an arbitrary file upload vulnerability.EPSS 1.9%9.8CVE-2022-24954Foxit pdf reader out-of-bounds write vulnerabilityFoxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have a Stack-Based Buffer Overflow related to XFA, for the 'subform colSpan="-2"' a…EPSS 12%9.8CVE-2022-24955Foxit pdf reader uncontrolled search path element vulnerabilityFoxit PDF Reader before 11.2.1 and Foxit PDF Editor before 11.2.1 have an Uncontrolled Search Path Element for DLL files.EPSS 1.1%9.8CVE-2021-38563Foxit pdf reader vulnerabilityAn issue was discovered in Foxit PDF Reader before 11.0.1 and PDF Editor before 11.0.1. It mishandles situations in which an array size (derived from…EPSS 1.1%8.8CVE-2025-13941Foxit pdf editor incorrect permission assignment vulnerabilityA local privilege escalation vulnerability exists in the Foxit PDF Reader/Editor Update Service. During plugin installation, incorrect file system pe…EPSS 0.19%8.8CVE-2025-32451Foxit pdf reader vulnerabilityA memory corruption vulnerability exists in Foxit Reader 2025.1.0.27937 due to the use of an uninitialized pointer. A specially crafted Javascript co…EPSS 0.58%8.8CVE-2024-47810Foxit pdf editor use after free vulnerabilityA use-after-free vulnerability exists in the way Foxit Reader 2024.3.0.26795 handles a 3D page object. A specially crafted Javascript code inside a m…EPSS 1.3%8.8CVE-2024-49576Foxit pdf editor use after free vulnerabilityA use-after-free vulnerability exists in the way Foxit Reader 2024.3.0.26795 handles a checkbox CBF_Widget object. A specially crafted Javascript cod…EPSS 1.1%

Source: NIST National Vulnerability Database (record CVE-2025-59802), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.