Description
An issue was discovered in Keyfactor SignServer before 7.6.0. The attribute ATTRIBUTESFILE in PKCS11CryptoToken can be set to a readable file but not an accepted file (i.e., recognized with attributes). In this case, an error is thrown which - together with the error - also prints the content of the file to the application server log. This gives a user that has both SignServer admin access and access to read the output of the server log (i.e., if remote syslog shipping is configured), the possibility to read the content of files accessible by the local user JBoss.
Published: 2026-09-15
Score: 4.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Confidentiality compromise from log-based file disclosure
Action: Patch
AI Analysis

Impact

An issue exists in Keyfactor SignServer versions before 7.6.0. When the ATTRIBUTESFILE parameter of the PKCS11CryptoToken is set to a readable file that is not a recognized attribute file, the token throws an exception. The exception handling logs the error message together with the complete content of that file to the application server log. An operator with SignServer administrative privileges and access to the server logs—either locally or via a remote syslog sink—can thus read arbitrary file contents that the local account used by the JBoss process can access.

Affected Systems

The vulnerability affects installations of Keyfactor SignServer that are configured with PKCS11CryptoToken and have ATTRIBUTESFILE pointing to a readable but non‑accepted file. The issue exists in all releases of SignServer prior to 7.6.0; later releases have fixed the handling of ATTRIBUTESFILE. Therefore any deployment running SignServer 7.5.x or earlier and using this configuration is potentially exposed.

Risk and Exploitability

Exploitation requires the attacker to possess SignServer administrative privileges and to be able to read the application server logs. The CVSS score of 4.9 indicates low severity. EPSS indicates a very low probability (<1 %), and the vulnerability is not listed in the CISA KEV catalog. However, environments that expose logs externally—such as through remote syslog shipping—or that lack strict log‑access controls at the operating‑system level may allow an insider or a compromised local user to capture sensitive file data. The impact is a confidentiality compromise of files readable by the JBoss user.

Generated by OpenCVE AI on September 22, 2026 at 17:33 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Install Keyfactor SignServer 7.6.0 or later, where the ATTRIBUTESFILE handling bug is fixed.
  • If an upgrade cannot be performed immediately, modify the PKCS11CryptoToken configuration to point ATTRIBUTESFILE only to valid attribute files or remove the setting; ensure the referenced file is not readable by non‑administrator users.
  • Restrict read access to the application server log files so that only authorized administrators can view them, and disable or secure remote syslog shipping to untrusted destinations.

Generated by OpenCVE AI on September 22, 2026 at 17:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 23 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 22 Sep 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 4.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N'}


Sun, 20 Sep 2026 18:45:00 +0000

Type Values Removed Values Added
Title Keyfactor SignServer Log Disclosure of Sensitive File Content via PKCS11CryptoToken
Weaknesses CWE-200
CWE-532

Thu, 17 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Title Keyfactor SignServer Log Leak Reveals Sensitive File Contents
Weaknesses CWE-200

Wed, 16 Sep 2026 07:15:00 +0000

Type Values Removed Values Added
Title Keyfactor SignServer Log Leak Reveals Sensitive File Contents
Weaknesses CWE-200

Tue, 15 Sep 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Keyfactor
Keyfactor signserver
Vendors & Products Keyfactor
Keyfactor signserver

Tue, 15 Sep 2026 14:45:00 +0000

Type Values Removed Values Added
Description An issue was discovered in Keyfactor SignServer before 7.6.0. The attribute ATTRIBUTESFILE in PKCS11CryptoToken can be set to a readable file but not an accepted file (i.e., recognized with attributes). In this case, an error is thrown which - together with the error - also prints the content of the file to the application server log. This gives a user that has both SignServer admin access and access to read the output of the server log (i.e., if remote syslog shipping is configured), the possibility to read the content of files accessible by the local user JBoss.
References

Subscriptions

Keyfactor Signserver
cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-09-22T15:46:12.233Z

Reserved: 2026-02-06T00:00:00.000Z

Link: CVE-2026-25826

cve-icon Vulnrichment

Updated: 2026-09-22T15:45:11.558Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-15T15:17:14.480

Modified: 2026-09-22T19:56:19.073

Link: CVE-2026-25826

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-22T17:45:17Z

Weaknesses
  • CWE-200

    Exposure of Sensitive Information to an Unauthorized Actor

  • CWE-532

    Insertion of Sensitive Information into Log File