CVE-2026-4947Disclosure(foxit / esign)

LOWCVSS 7.1 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Addressed a potential insecure direct object reference (IDOR) vulnerability in the signing invitation acceptance process. Under certain conditions, this issue could have allowed an attacker to access or modify unauthorized resources by manipulating user-supplied object identifiers, potentially leading to forged signatures and compromising the integrity and authenticity of documents undergoing the signing process. The issue was caused by insufficient authorization validation on referenced resources during request processing.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-284

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • esign

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
esign

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-01: 3Technical Details · 2026-04-01: 204-01
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVE@CVEnew
    General

    CVE-2026-4947 Addressed a potential insecure direct object reference (IDOR) vulnerability in the signing invitation acceptance process. Under certain conditions, this issue could hav… https://www.cve.org/CVERecord?id=CVE-2026-4947

    Post summary

    The content delivers a brief acknowledgment of CVE-2026-4947 as an IDOR vulnerability in a signing process, without providing additional technical insight, exploit details, or mitigation information.

    00010122
    56.9K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-4947 📊 Severity: 7.1 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4947 #CVE-2026-4947 #CVE #High #CyberSecurity #InfoSec https://t.co/w6WTmD9Rrk

    Post summary

    A new vulnerability, CVE-2026-4947, is announced with a severity of 7.1 impacting unspecified products; no PoC, exploit, or mitigation details are provided.

    0000033
    123 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4947 - Insecure Direct Object Reference (IDOR) Leading to Signature Forgery in Foxit eSign Intel Report: https://ift.tt/cqazReS

    Post summary

    An Intel report announces a new IDOR vulnerability (CVE‑2026‑4947) in Foxit eSign capable of forging signatures.

    0000034
    281 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appfoxitesign---

Explore more