HIGHVulnerability

CVE-2026-72691

An authentication bypass vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to mint MASTER_KEY-signed file access tokens for arbitrary stored files via the getsignedurl Parse cloud function. The function skips its isAuthenticated check whenever any docId parameter is supplied, even one corresponding to no real document, allowing the authentication gate to be bypassed by supplying an arbitrary string as docId.

Properties

severity
HIGH
score
7.5
cve_id
CVE-2026-72691
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
published_at
2026-08-10T13:20:39.350
last_modified
2026-08-26T17:36:16.900

Related Entities (2)

HAS_WEAKNESS (1)

[Weakness]Authentication Bypass Using an Alternate Path or Channel

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-72691 — Ninja Signal Threat Intelligence | Ninja Signal