CVE-2026-72692: Opensignlabs Opensignserver
High severity, CVSS 7.5. EPSS: 0.4% chance of exploitation in the next 30 days.
A missing authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to irreversibly decline any in-flight document and forge the decline attribution to an arbitrary user via the declinedoc Parse cloud function. The function writes IsDeclined, DeclineReason, and a caller-supplied DeclineBy pointer without verifying the caller's identity, enabling workflow termination and evidentiary record falsification against any accessible document.
Affected products
- Opensignlabs Opensignserver: up to and including 2.37.0
Published 2026-08-10. Last modified 2026-08-26.