Authentication Vulnerability in OpenSignLabs OpenSignServer
CVE-2026-72688

7.5HIGH

Key Information:

Vendor
CVE Published:
10 August 2026

What is CVE-2026-72688?

OpenSignLabs OpenSignServer contains a vulnerability that permits an unauthenticated remote attacker to gain access to arbitrary stored documents. This flaw stems from the fileupload Parse cloud function, which can generate MASTER_KEY-signed file access tokens for any URL provided by the attacker without verifying the session. This lack of session validation effectively undermines the access control measures meant to protect stored contract files, posing a significant risk to sensitive data.

Affected Version(s)

opensignserver 0 <= 2.37.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bobur Abdugafforov (Mahadsec)
.