PT-2026-69833 · Git+1 · Opensign+1
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
opensignserver versions prior to 2.37.1
Description
A missing authorization issue allows an unauthenticated remote attacker to irreversibly decline any in-flight document and forge the decline attribution to an arbitrary user. This is possible through the
declinedoc Parse cloud function, which writes IsDeclined, DeclineReason, and a caller-supplied DeclineBy pointer without verifying the identity of the caller. This flaw enables the termination of workflows and the falsification of evidentiary records for any accessible document.Recommendations
Update opensignserver to version 2.37.1 or later.
As a temporary mitigation, restrict access to the
declinedoc Parse cloud function.Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opensign
Opensignserver