Description
Improper verification of cryptographic signature and Improper Check for Unusual or Exceptional Conditions vulnerability in Estonian Information System Authority (RIA) libdigidocpp, DigiDoc4, DigiDoc on Android, and DigiDoc on iOS. This issue affects libdigidocpp: from 4.1.0 before 4.2.1; DigiDoc4: from 4.7.0 before 4.8.2; DigiDoc on Android: from 2.7.0 before 2.7.2; DigiDoc on iOS: from 2.8.0 before 2.8.1.
Published: 2026-08-10
Score: 4.4 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from improper verification of cryptographic signatures and a failure to detect unusual or exceptional conditions during signature validation in Estonian Information System Authority’s libraries and applications. Based on the description, it is inferred that an attacker who can supply a manipulated signature or document might cause the software to accept a forged signature, allowing creation or alteration of digitally signed documents that appear legitimate, thereby undermining the integrity and authenticity guarantees that the DigiDoc ecosystem is designed to provide.

Affected Systems

The weakness affects libdigidocpp on versions 4.1.0 up to but not including 4.2.1; DigiDoc4 on versions 4.7.0 up to 4.8.1; DigiDoc Android on versions 2.7.0 up to 2.7.1; DigiDoc iOS on versions 2.8.0 up to 2.8.0. The products are part of the Estonian Information System Authority’s DigiDoc suite.

Risk and Exploitability

The CVSS base score of 4.4 indicates a low severity impact, and there is no EPSS data nor KEV listing, suggesting that no widespread exploitation has been observed. Nevertheless, based on the description, it is inferred that the flaw can be exploited by an attacker who can present a forged document to a user running one of the affected applications, thereby causing the signature to be accepted as valid. The likely attack vector involves the attacker supplying a document or signature that the vulnerable component will process, which is typically possible in environments where users open documents from untrusted sources or the software automatically verifies incoming signatures.

Generated by OpenCVE AI on August 10, 2026 at 18:41 UTC.

Remediation

Vendor Solution

Systems integrating libdigidocpp should update to version 4.2.1 or later.  Users of DigiDoc applications should update to fixed versions provided by the vendor:  DigiDoc4 - 4.8.2 or later, RIA DigiDoc Android - 2.7.2 or later, and RIA DigiDoc iOS - 2.8.1 or later.  Signatures that were validated with the vulnerable software versions should be revalidated.


OpenCVE Recommended Actions

  • Update libdigidocpp to version 4.2.1 or newer.
  • Update DigiDoc4 to 4.8.2 or newer.
  • Update DigiDoc Android to 2.7.2 or newer.
  • Update DigiDoc iOS to 2.8.1 or newer.
  • Re‑validate any documents whose signatures were previously approved with vulnerable versions.

Generated by OpenCVE AI on August 10, 2026 at 18:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 10 Aug 2026 14:15:00 +0000

Type Values Removed Values Added
Description Improper verification of cryptographic signature and Improper Check for Unusual or Exceptional Conditions vulnerability in Estonian Information System Authority (RIA) libdigidocpp, DigiDoc4, DigiDoc on Android, and DigiDoc on iOS. This issue affects libdigidocpp: from 4.1.0 before 4.2.1; DigiDoc4: from 4.7.0 before 4.8.2; DigiDoc on Android: from 2.7.0 before 2.7.2; DigiDoc on iOS: from 2.8.0 before 2.8.1.
Title Signature validation vulnerability affecting DigiDoc applications
Weaknesses CWE-347
CWE-754
References
Metrics cvssV4_0

{'score': 4.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: ENISA

Published:

Updated: 2026-08-10T17:55:30.587Z

Reserved: 2026-07-02T15:47:36.965Z

Link: CVE-2026-59112

cve-icon Vulnrichment

Updated: 2026-08-10T17:55:24.289Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-10T18:45:17Z

Weaknesses
  • CWE-347

    Improper Verification of Cryptographic Signature

  • CWE-754

    Improper Check for Unusual or Exceptional Conditions