PatchSiren cyber security CVE debrief
CVE-2026-57917 Asseco CVE debrief
proCertum SmartSign contains an XML External Entity (XXE) vulnerability. The issue allows for Server-Side Request Forgery (SSRF) and potentially enables reading of local files, depending on the parser's configuration. The vulnerability is triggered by previewing a crafted signature file in the file selection window, before opening it. This issue was fixed in version 9.4.3.90. The vulnerability can lead to SSRF attacks and potentially allow the reading of local files if the XML parser configuration allows it.
- Vendor
- Asseco
- Product
- proCertum SmartSign
- CVSS
- MEDIUM 4.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-27
- Original CVE updated
- 2026-07-27
- Advisory published
- 2026-07-27
- Advisory updated
- 2026-07-27
Who should care
Users of proCertum SmartSign, especially those handling sensitive data or requiring secure file processing, should prioritize updating to version 9.4.3.90 or later. This is crucial for organizations that process sensitive information and require secure file handling to prevent potential SSRF attacks and unauthorized local file access.
Technical summary
The proCertum SmartSign application is vulnerable to an XML External Entity (XXE) attack. This vulnerability, identified as CVE-2026-57917, occurs when the application parses external XML entities from arbitrary crafted signature files. The XXE vulnerability can lead to Server-Side Request Forgery (SSRF) attacks and potentially allow the reading of local files, depending on the configuration of the XML parser being used. The vulnerability can be exploited simply by previewing a maliciously crafted file in the file selection window, prior to clicking 'Open'. This issue has been addressed in version 9.4.3.90 of the software.
Defensive priority
Medium priority due to the potential for SSRF and local file access. Organizations should prioritize updates and implement additional security measures to mitigate potential risks.
Recommended defensive actions
- Update proCertum SmartSign to version 9.4.3.90 or later
- Restrict access to sensitive files and directories
- Implement network monitoring for suspicious activity
- Validate and sanitize XML inputs
- Consider using XML parsers that do not support external entities
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
Evidence is based on limited information from CVE and NVD sources. Further verification is recommended. The vulnerability allows for Server-Side Request Forgery (SSRF) and potentially enables reading of local files, depending on the parser's configuration. The XML External Entity (XXE) vulnerability is triggered simply by previewing a file in the file selection window, before the victim clicks 'Open'.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-07-27T12:16:46.400Z and has not been modified since then.