Insecure Direct Object Reference in OpenSignLabs OpenSign Affects Data Integrity
CVE-2026-72545
7.5HIGH
What is CVE-2026-72545?
An insecure direct object reference (IDOR) vulnerability in OpenSignLabs OpenSign allows unauthenticated remote attackers to manipulate contact records via the updatecontacttour Parse cloud function. This flaw permits unauthorized users to overwrite contact data of any account, leading to potential corruption of sensitive information without the need for valid credentials.
Affected Version(s)
OpenSign 0 <= 2.37.0
