OpnForm derives editable-submission secrets from sequential row identifiers using Hashids with an empty default salt, allowing unauthenticated attackers to compute hashes for any submission. Attackers can read other respondents' full submission data through the submission-fetch endpoint or overwrite submissions by supplying predicted hashes to the answer endpoint.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-17 21:16
Updated : 2026-08-18 15:17
NVD link : CVE-2026-75106
Mitre link : CVE-2026-75106
CVE.ORG link : CVE-2026-75106
JSON object : View
Products Affected
No product.
CWE
CWE-340
Generation of Predictable Numbers or Identifiers
