PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-57917 Asseco CVE debrief

proCertum SmartSign contains an XML External Entity (XXE) vulnerability. The issue allows for Server-Side Request Forgery (SSRF) and potentially enables reading of local files, depending on the parser's configuration. The vulnerability is triggered by previewing a crafted signature file in the file selection window, before opening it. This issue was fixed in version 9.4.3.90. The vulnerability can lead to SSRF attacks and potentially allow the reading of local files if the XML parser configuration allows it.

Vendor
Asseco
Product
proCertum SmartSign
CVSS
MEDIUM 4.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-27
Original CVE updated
2026-07-27
Advisory published
2026-07-27
Advisory updated
2026-07-27

Who should care

Users of proCertum SmartSign, especially those handling sensitive data or requiring secure file processing, should prioritize updating to version 9.4.3.90 or later. This is crucial for organizations that process sensitive information and require secure file handling to prevent potential SSRF attacks and unauthorized local file access.

Technical summary

The proCertum SmartSign application is vulnerable to an XML External Entity (XXE) attack. This vulnerability, identified as CVE-2026-57917, occurs when the application parses external XML entities from arbitrary crafted signature files. The XXE vulnerability can lead to Server-Side Request Forgery (SSRF) attacks and potentially allow the reading of local files, depending on the configuration of the XML parser being used. The vulnerability can be exploited simply by previewing a maliciously crafted file in the file selection window, prior to clicking 'Open'. This issue has been addressed in version 9.4.3.90 of the software.

Defensive priority

Medium priority due to the potential for SSRF and local file access. Organizations should prioritize updates and implement additional security measures to mitigate potential risks.

Recommended defensive actions

  • Update proCertum SmartSign to version 9.4.3.90 or later
  • Restrict access to sensitive files and directories
  • Implement network monitoring for suspicious activity
  • Validate and sanitize XML inputs
  • Consider using XML parsers that do not support external entities
  • Review compensating controls for exposed systems while remediation is scheduled and verified
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

Evidence is based on limited information from CVE and NVD sources. Further verification is recommended. The vulnerability allows for Server-Side Request Forgery (SSRF) and potentially enables reading of local files, depending on the parser's configuration. The XML External Entity (XXE) vulnerability is triggered simply by previewing a file in the file selection window, before the victim clicks 'Open'.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-27T12:16:46.400Z and has not been modified since then.