Description
OpenSign through 2.41.3 fails to validate caller identity in the getDocument cloud function when one-time-password verification is disabled. Attackers can supply a document identifier from guest signing links to retrieve complete document details including all signers' information, sender identity, and valid download tokens without authentication.
No analysis available yet.
Remediation
No remediation available yet.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Wed, 16 Sep 2026 20:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | OpenSign through 2.41.3 fails to validate caller identity in the getDocument cloud function when one-time-password verification is disabled. Attackers can supply a document identifier from guest signing links to retrieve complete document details including all signers' information, sender identity, and valid download tokens without authentication. | |
| Title | OpenSign through 2.41.3 Information Disclosure via getDocument | |
| Weaknesses | CWE-862 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-09-16T20:32:48.996Z
Reserved: 2026-09-16T19:40:20.554Z
Link: CVE-2026-92794
No data.
Status : Received
Published: 2026-09-16T21:17:29.073
Modified: 2026-09-16T21:17:29.073
Link: CVE-2026-92794
No data.
OpenCVE Enrichment
No data.
Weaknesses
-
CWE-862
Missing Authorization