PT-2026-94071 · Opensignlabs+1 · Opensign

·

CVE-2026-92794

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions OpenSign versions prior to 2.41.4
Description The getDocument cloud function fails to validate the identity of the caller when one-time-password verification is disabled. An attacker can provide a document identifier obtained from guest signing links to retrieve comprehensive document details without authentication. This information includes the identity of the sender, details of all signers, and valid download tokens.
Recommendations Update OpenSign to version 2.41.4 or later. As a temporary mitigation, enable one-time-password verification for the getDocument function.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92794

Affected Products

Opensign