PT-2026-64888 · Procertum · Procertum Smartsign

·

CVE-2026-57916

·

Published

2026-07-27

·

Updated

2026-07-27

CVSS v4.0

4.6

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions proCertum SmartSign versions prior to 9.4.3.90
Description The application opens the Certificate Practice Statement (CPS) URI without performing schema validation. This allows an attacker to create a certificate containing a CPS URI that points to a local executable file or an arbitrary URL. If a victim opens a document signed with this certificate, the application will execute the specified file or open the webpage.
Recommendations Update to version 9.4.3.90.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-57916

Affected Products

Procertum Smartsign