A broken object-level authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to read complete contract records via the getDocument Parse cloud function. The function fetches documents using useMasterKey, bypassing the object ACL, and returns full records including sender and signer PII and a pre-signed document download URL whenever the document's IsEnableOTP flag is unset, which is the default configuration.
References
| Link | Resource |
|---|---|
| https://github.com/OpenSignLabs/OpenSign |
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-10 13:20
Updated : 2026-08-26 17:36
NVD link : CVE-2026-72689
Mitre link : CVE-2026-72689
CVE.ORG link : CVE-2026-72689
JSON object : View
Products Affected
No product.
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
