Information Disclosure Vulnerability in OpenSignLabs OpenSign Product
CVE-2026-72548

7.5HIGH

Key Information:

Status
Vendor
CVE Published:
11 August 2026

What is CVE-2026-72548?

OpenSignLabs OpenSign product version 2.37.0 is susceptible to an information disclosure vulnerability that enables unauthenticated remote attackers to access any organization's tenant records through the gettenant Parse cloud function. This flawed function accepts a contactId parameter and, without any form of authentication or authorization checks, exposes the complete tenant record. This oversight allows attackers to enumerate and extract sensitive tenant configuration data from any organization within the system, posing a significant security risk.

Affected Version(s)

OpenSign 0 <= 2.37.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bobur Abdugafforov (Mahadsec)
.