MEDIUMVulnerability

CVE-2026-72549

An information disclosure vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to map any email address or username to its internal user objectId via the getUserId Parse cloud function. The function performs no authentication before resolving and returning the internal identifier. An attacker can use this to enumerate user accounts and target subsequent attacks.

Properties

severity
MEDIUM
score
5.3
epss_score
0.00355
cve_id
CVE-2026-72549
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
published_at
2026-08-11T12:17:40.483
last_modified
2026-09-03T17:51:46.420
epss_percentile
0.28429

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Exposure of Sensitive Information to an Unauthorized Actor

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-72549 — Ninja Signal Threat Intelligence | Ninja Signal