Impact
A missing authorization check in OpenSignLabs opensignserver allows an unauthenticated remote attacker to irreversibly mark any in‑flight document as declined and to forge the declined document’s attribution to an arbitrary user via the declinedoc Parse cloud function. The function writes IsDeclined, DeclineReason, and a caller‑supplied DeclineBy pointer without validating the caller’s identity, thereby terminating the workflow and contaminating the evidence trail for any document accessible to the attacker.
Affected Systems
The vulnerability affects OpenSignLabs opensignserver versions through 2.37.0. Any installation running these versions without an updated patch is potentially vulnerable.
Risk and Exploitability
The CVSS score of 7.5 indicates a high impact severity. EPSS is not available, but the absence of a KEV listing suggests no public exploitation reports yet. The flaw is exploitable over the network from any remote host that can invoke the declinedoc API endpoint, requiring no authentication. Successful exploitation would give the attacker full control over document lifecycle and the ability to falsify audit trails.
OpenCVE Enrichment