CVE-2026-92794: Opensignlabs Opensign
High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.
OpenSign through 2.41.3 fails to validate caller identity in the getDocument cloud function when one-time-password verification is disabled. Attackers can supply a document identifier from guest signing links to retrieve complete document details including all signers' information, sender identity, and valid download tokens without authentication.
Affected products
- Opensignlabs Opensign: up to and including 2.41.3
Published 2026-09-16. Last modified 2026-09-22.