A missing authentication vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to read arbitrary stored documents via the fileupload Parse cloud function. The function mints MASTER_KEY-signed file access tokens for any caller-supplied URL without performing any session check, defeating the only access control protecting stored contract files.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://github.com/OpenSignLabs/OpenSign |
|
History
Tue, 11 Aug 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Opensignlabs
Opensignlabs opensignserver |
|
| Vendors & Products |
Opensignlabs
Opensignlabs opensignserver |
Mon, 10 Aug 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 10 Aug 2026 12:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A missing authentication vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to read arbitrary stored documents via the fileupload Parse cloud function. The function mints MASTER_KEY-signed file access tokens for any caller-supplied URL without performing any session check, defeating the only access control protecting stored contract files. | |
| Title | OpenSignLabs opensignserver - Missing Authentication for Critical Function | |
| Weaknesses | CWE-306 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: TuranSec
Published: 2026-08-10T11:59:02.770Z
Updated: 2026-08-10T18:22:30.882Z
Reserved: 2026-08-10T11:55:39.470Z
Link: CVE-2026-72688
Updated: 2026-08-10T15:51:49.926Z
Status : Received
Published: 2026-08-10T13:20:38.987
Modified: 2026-08-10T19:17:33.003
Link: CVE-2026-72688
No data.