CVE Explorer
CVE-2026-4947
Addressed a potential insecure direct object reference (IDOR) vulnerability in the signing invitation acceptance process. Under certain conditions, this issue could have allowed an attacker to access or modify unauthorized resources by manipulating user-supplied object identifiers, potentially leading to forged signatures and compromising the integrity and authenticity of documents undergoing the signing process. The issue was caused by insufficient authorization validation on referenced resourc
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"na1.foxitesign.foxit.com","vendor":"Foxit Software Inc.","versions":[{"status":"affected","version":"before 2026-03-26"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:4e940de85498aaf42ae6864ea611371070ed4ac0b066ba0e41fd66b57d3f9bb9 · sha256:a1fd07283d3ad472… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":7.1,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:L/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:4e940de85498aaf42ae6864ea611371070ed4ac0b066ba0e41fd66b57d3f9bb9 · sha256:a1fd07283d3ad472… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-284","description":"CWE-284: Improper Access Control","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:4e940de85498aaf42ae6864ea611371070ed4ac0b066ba0e41fd66b57d3f9bb9 · sha256:a1fd07283d3ad472… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"url":"https://www.foxit.com/support/security-bulletins.html"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:4e940de85498aaf42ae6864ea611371070ed4ac0b066ba0e41fd66b57d3f9bb9 · sha256:a1fd07283d3ad472… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.