PT-2026-94071 · Opensignlabs+1 · Opensign
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
OpenSign versions prior to 2.41.4
Description
The
getDocument cloud function fails to validate the identity of the caller when one-time-password verification is disabled. An attacker can provide a document identifier obtained from guest signing links to retrieve comprehensive document details without authentication. This information includes the identity of the sender, details of all signers, and valid download tokens.Recommendations
Update OpenSign to version 2.41.4 or later.
As a temporary mitigation, enable one-time-password verification for the
getDocument function.Exploit
Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Opensign