PT-2026-69833 · Git+1 · Opensign+1

·

CVE-2026-72692

·

Published

2026-08-10

·

Updated

2026-08-10

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Name of the Vulnerable Software and Affected Versions opensignserver versions prior to 2.37.1
Description A missing authorization issue allows an unauthenticated remote attacker to irreversibly decline any in-flight document and forge the decline attribution to an arbitrary user. This is possible through the declinedoc Parse cloud function, which writes IsDeclined, DeclineReason, and a caller-supplied DeclineBy pointer without verifying the identity of the caller. This flaw enables the termination of workflows and the falsification of evidentiary records for any accessible document.
Recommendations Update opensignserver to version 2.37.1 or later. As a temporary mitigation, restrict access to the declinedoc Parse cloud function.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-72692

Affected Products

Opensign
Opensignserver