PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-5414 Newgen CVE debrief

CVE-2026-5414 is a MEDIUM severity vulnerability in Newgen OmniDocs up to 12.0.00. The issue is related to improper control of resource identifiers in the /omnidocs/WebApiRequestRedirection file. The attack may be performed from remote. The exploit has been released to the public, and defenders should take necessary actions to mitigate the risk. Affected users should review the official advisory and apply patches or updates if available. Compensating controls, such as restricting access to /omnidocs/WebApiRequestRedirection, should be implemented while remediation is scheduled and verified.

Vendor
Newgen
Product
OmniDocs
CVSS
MEDIUM 5.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-04-02
Original CVE updated
2026-07-24
Advisory published
2026-04-02
Advisory updated
2026-07-24

Who should care

Users of Newgen OmniDocs up to version 12.0.00 should be aware of this vulnerability and take necessary actions to mitigate the risk. Affected operators, platforms, and security teams should review the official advisory and apply patches or updates if available. Vulnerability management and security teams should prioritize this vulnerability due to its MEDIUM severity and remote attack vector.

Technical summary

A security flaw has been discovered in Newgen OmniDocs up to 12.0.00. Affected by this issue is some unknown functionality of the file /omnidocs/WebApiRequestRedirection. The manipulation of the argument DocumentId results in improper control of resource identifiers. The attack may be performed from remote. The vulnerability has a MEDIUM severity score of 5.5. Defenders should focus on patching or mitigating this vulnerability, as the exploit has been released to the public.

Defensive priority

Medium priority due to the remote attack vector and publicly available exploit. Defenders should prioritize patching or mitigating this vulnerability.

Recommended defensive actions

  • Inventory and verify affected Newgen OmniDocs installations
  • Apply vendor patches or updates if available
  • Implement compensating controls to restrict access to /omnidocs/WebApiRequestRedirection
  • Monitor for suspicious activity related to DocumentId manipulation
  • Consider exception tracking for unusual resource identifier usage
  • Review relevant monitoring, detection, and logs for exposed assets that need extra review
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented

Evidence notes

The CVE record was published on 2026-04-02T18:16:35.777Z and was last modified on 2026-07-24T20:10:00.147Z. The NVD entry is currently Deferred. The source details are limited, and defenders should verify the affected scope and severity with the vendor or other trusted sources. The exploit has been released to the public, and defenders should prioritize patching or mitigating this vulnerability. Evidence limits suggest that the vulnerability is in the /omnidocs/WebApiRequestRedirection file, but further details are not available.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-02T18:16:35.777Z and has not been modified since then. The NVD entry is currently Deferred.