Unauthenticated File Upload Vulnerability in Documenso by Documenso
CVE-2026-82472
8.7HIGH
What is CVE-2026-82472?
Documenso versions prior to 2.13.0 are susceptible to an unauthenticated file upload vulnerability that allows malicious users to upload arbitrary PDF files via the /api/files/upload-pdf endpoint. This security flaw bypasses authentication mechanisms, enabling attackers to exploit the system's resources by continually uploading files, which can lead to storage exhaustion and an accumulation of unlinked document records in the database.
Affected Version(s)
documenso 0 < 2.13.0
