Improper Access Control in Documenso Live Document Signing UI
CVE-2026-71247

6.5MEDIUM

Key Information:

Vendor

Documenso

Status
Vendor
CVE Published:
5 August 2026

What is CVE-2026-71247?

The Documenso live document-signing interface has a serious security weakness, allowing users with the ASSISTANT role to access and complete signature fields assigned to other signers within the same envelope, regardless of those fields' type. This lack of restriction means that an ASSISTANT recipient can inadvertently or maliciously forge another user's signature, as there are no sufficient checks to ensure that the acting recipient has the right to access the signature fields they are manipulating. The issue is not present in the newer signing implementation, revealing a significant oversight in the older version of the product.

Affected Version(s)

documenso 0

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bobur Abdugafforov
.