CVE-2026-72688

A missing authentication vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to read arbitrary stored documents via the fileupload Parse cloud function. The function mints MASTER_KEY-signed file access tokens for any caller-supplied URL without performing any session check, defeating the only access control protecting stored contract files.
References
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-10 13:20

Updated : 2026-08-26 17:36


NVD link : CVE-2026-72688

Mitre link : CVE-2026-72688

CVE.ORG link : CVE-2026-72688


JSON object : View

Products Affected

No product.

CWE
CWE-306

Missing Authentication for Critical Function