Improper Access Control in Documenso Live Document Signing UI
CVE-2026-71247
6.5MEDIUM
What is CVE-2026-71247?
The Documenso live document-signing interface has a serious security weakness, allowing users with the ASSISTANT role to access and complete signature fields assigned to other signers within the same envelope, regardless of those fields' type. This lack of restriction means that an ASSISTANT recipient can inadvertently or maliciously forge another user's signature, as there are no sufficient checks to ensure that the acting recipient has the right to access the signature fields they are manipulating. The issue is not present in the newer signing implementation, revealing a significant oversight in the older version of the product.
Affected Version(s)
documenso 0
