PT-2026-70124 · Opensignlabs · Opensign

·

CVE-2026-72549

·

Published

2026-08-11

·

Updated

2026-08-11

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions OpenSignLabs OpenSign versions prior to 2.37.1
Description An information disclosure issue exists where unauthenticated remote attackers can map any email address or username to its internal user objectId via the getUserId() Parse cloud function. The function fails to perform authentication before resolving and returning the internal identifier, which allows for the enumeration of user accounts to facilitate subsequent attacks.
Recommendations Update OpenSignLabs OpenSign to version 2.37.1 or later. As a temporary workaround, restrict access to the getUserId() function until the update is applied.

Exploit

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-72549

Affected Products

Opensign