PT-2026-69829 · Git+1 · Opensign+1

·

CVE-2026-72688

·

Published

2026-08-10

·

Updated

2026-08-10

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions opensignserver versions prior to 2.37.1
Description A missing authentication issue allows an unauthenticated remote attacker to read arbitrary stored documents. This occurs via the fileupload Parse cloud function, which generates file access tokens signed with the MASTER KEY for any URL provided by the caller without performing a session check. This bypasses the primary access control mechanism protecting stored contract files.
Recommendations Update opensignserver to version 2.37.1 or later. As a temporary mitigation, restrict access to the fileupload Parse cloud function.

Exploit

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-72688

Affected Products

Opensign
Opensignserver