Information Disclosure Vulnerability in OpenSignLabs OpenSign
CVE-2026-72549
5.3MEDIUM
What is CVE-2026-72549?
An unauthorized information disclosure vulnerability exists in OpenSignLabs OpenSign versions up to 2.37.0. This flaw allows remote attackers to exploit the getUserId Parse cloud function without any authentication, enabling them to link any email address or username to its associated internal user objectId. This can lead to account enumeration and may facilitate further targeted attacks by malicious actors.
Affected Version(s)
OpenSign 0 <= 2.37.0
