CVE-2026-92794EPSS p46.5%
CVE-2026-92794CVE-2026-92794
Description
OpenSign through 2.41.3 fails to validate caller identity in the getDocument cloud function when one-time-password verification is disabled. Attackers can supply a document identifier from guest signing links to retrieve complete document details including all signers' information, sender identity, and valid download tokens without authentication.
Scoring
| CVSS | 7.5 () |
| Vector | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
| EPSS | 0.59% probability of exploitation · percentile 46.5% · 2026-10-05T12:00:23Z |
| Last modified | 2026-09-22 |