Authentication Vulnerability in OpenSignLabs OpenSignServer
CVE-2026-72688
7.5HIGH
What is CVE-2026-72688?
OpenSignLabs OpenSignServer contains a vulnerability that permits an unauthenticated remote attacker to gain access to arbitrary stored documents. This flaw stems from the fileupload Parse cloud function, which can generate MASTER_KEY-signed file access tokens for any URL provided by the attacker without verifying the session. This lack of session validation effectively undermines the access control measures meant to protect stored contract files, posing a significant risk to sensitive data.
Affected Version(s)
opensignserver 0 <= 2.37.0
