Description
A critical Remote Code Execution (RCE) vulnerability exists in Disig Web Signer versions 2.0.3 through 2.5.3.
Published: 2026-06-01
Score: 9.4 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in Disig Web Signer allows an attacker to execute arbitrary code on the host system. The flaw is present in versions 2.0.3 through 2.5.3 and can be triggered by a remote attacker.

Affected Systems

Disig Web Signer versions 2.0.3 to 2.5.3 are affected. No other vendors or product lines are listed as impacted.

Risk and Exploitability

The CVSS score of 9.4 indicates critical severity. EPSS data is not available, so the exploitation probability is unknown, but the absence from the KEV catalog does not negate risk. The likely attack vector is a remote user submitting a crafted request to the Web Signer application, probably via its web UI or API endpoint. Successful exploitation could give the attacker a full shell on the system hosting the application.

Generated by OpenCVE AI on June 1, 2026 at 17:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Disig Web Signer update that includes the fix for the RCE (any release 2.6.0 or newer).
  • If a swift upgrade is not possible, restrict external access to the Web Signer service by applying firewall rules that allow traffic only from trusted IP addresses or by placing the service behind a VPN.
  • Deploy a web application firewall or similar protection to detect and block anomalous or malicious requests targeting Web Signer endpoints.

Generated by OpenCVE AI on June 1, 2026 at 17:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 03 Jun 2026 02:30:00 +0000

Type Values Removed Values Added
First Time appeared Disig
Disig web Signer
Vendors & Products Disig
Disig web Signer

Mon, 01 Jun 2026 16:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-94
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 01 Jun 2026 15:00:00 +0000

Type Values Removed Values Added
Description A critical Remote Code Execution (RCE) vulnerability exists in Disig Web Signer versions 2.0.3 through 2.5.3.
Title Critical RCE vulnerability in Disig Web Signer
References
Metrics cvssV4_0

{'score': 9.4, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

Disig Web Signer
cve-icon MITRE

Status: PUBLISHED

Assigner: SK-CERT

Published:

Updated: 2026-06-01T15:31:51.875Z

Reserved: 2026-05-19T08:34:36.546Z

Link: CVE-2026-8931

cve-icon Vulnrichment

Updated: 2026-06-01T15:31:43.494Z

cve-icon NVD

Status : Deferred

Published: 2026-06-01T15:16:39.220

Modified: 2026-06-01T18:09:48.420

Link: CVE-2026-8931

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-02T20:54:31Z

Weaknesses
  • CWE-94

    Improper Control of Generation of Code ('Code Injection')