Unauthenticated File Upload Vulnerability in Documenso by Documenso
CVE-2026-82472

8.7HIGH

Key Information:

Vendor

Documenso

Status
Vendor
CVE Published:
29 August 2026

What is CVE-2026-82472?

Documenso versions prior to 2.13.0 are susceptible to an unauthenticated file upload vulnerability that allows malicious users to upload arbitrary PDF files via the /api/files/upload-pdf endpoint. This security flaw bypasses authentication mechanisms, enabling attackers to exploit the system's resources by continually uploading files, which can lead to storage exhaustion and an accumulation of unlinked document records in the database.

Affected Version(s)

documenso 0 < 2.13.0

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.