Impact
OptimiDoc Server stores credentials for external services such as SMTP, FTP, Active Directory, and SharePoint in cleartext, allowing an authenticated administrator to view the passwords in the web administration panel’s page source. This flaw results in the disclosure of confidential third‑party authentication data and is identified as a CWE‑256 (Sensitive Data Exposure).
Affected Systems
The vulnerability affects OptimiDoc Server (On‑Premise) across all versions that lack the 26.08 update. Administrators with authorized access to the web interface can exploit the flaw to retrieve stored passwords.
Risk and Exploitability
The CVSS score of 6.9 indicates a moderate to high risk. The EPSS score is not available and the flaw is not listed in the CISA KEV catalog, implying no evidence of widespread exploitation yet. The attack vector is inferred to be a local privilege escalation that requires valid administrative credentials on the web interface; thus, the threat is limited to individuals who can authenticate as an administrator.
OpenCVE Enrichment