PT-2026-68113 · Documenso · Documenso

·

CVE-2026-71247

·

Published

2026-08-05

·

Updated

2026-08-10

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions Documenso (affected versions not specified)
Description In the live document-signing UI, the sign-field-with-token.ts handler allows a recipient with the ASSISTANT role to fetch and complete fields belonging to any not-yet-signed recipient in the same envelope who has a later or equal signing order. This occurs because the handler upserts a Signature record tied to the target field's recipientId without verifying if the field.type is SIGNATURE or if the acting recipient owns the field. Consequently, in sequential-signing documents, an assistant recipient can forge the signature field of another signer.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-71247

Affected Products

Documenso