PT-2026-69829 · Git+1 · Opensign+1
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
opensignserver versions prior to 2.37.1
Description
A missing authentication issue allows an unauthenticated remote attacker to read arbitrary stored documents. This occurs via the
fileupload Parse cloud function, which generates file access tokens signed with the MASTER KEY for any URL provided by the caller without performing a session check. This bypasses the primary access control mechanism protecting stored contract files.Recommendations
Update opensignserver to version 2.37.1 or later.
As a temporary mitigation, restrict access to the
fileupload Parse cloud function.Exploit
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opensign
Opensignserver