PatchSiren cyber security CVE debrief
CVE-2026-5414 Newgen CVE debrief
CVE-2026-5414 is a MEDIUM severity vulnerability in Newgen OmniDocs up to 12.0.00. The issue is related to improper control of resource identifiers in the /omnidocs/WebApiRequestRedirection file. The attack may be performed from remote. The exploit has been released to the public, and defenders should take necessary actions to mitigate the risk. Affected users should review the official advisory and apply patches or updates if available. Compensating controls, such as restricting access to /omnidocs/WebApiRequestRedirection, should be implemented while remediation is scheduled and verified.
- Vendor
- Newgen
- Product
- OmniDocs
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-02
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-02
- Advisory updated
- 2026-07-24
Who should care
Users of Newgen OmniDocs up to version 12.0.00 should be aware of this vulnerability and take necessary actions to mitigate the risk. Affected operators, platforms, and security teams should review the official advisory and apply patches or updates if available. Vulnerability management and security teams should prioritize this vulnerability due to its MEDIUM severity and remote attack vector.
Technical summary
A security flaw has been discovered in Newgen OmniDocs up to 12.0.00. Affected by this issue is some unknown functionality of the file /omnidocs/WebApiRequestRedirection. The manipulation of the argument DocumentId results in improper control of resource identifiers. The attack may be performed from remote. The vulnerability has a MEDIUM severity score of 5.5. Defenders should focus on patching or mitigating this vulnerability, as the exploit has been released to the public.
Defensive priority
Medium priority due to the remote attack vector and publicly available exploit. Defenders should prioritize patching or mitigating this vulnerability.
Recommended defensive actions
- Inventory and verify affected Newgen OmniDocs installations
- Apply vendor patches or updates if available
- Implement compensating controls to restrict access to /omnidocs/WebApiRequestRedirection
- Monitor for suspicious activity related to DocumentId manipulation
- Consider exception tracking for unusual resource identifier usage
- Review relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
Evidence notes
The CVE record was published on 2026-04-02T18:16:35.777Z and was last modified on 2026-07-24T20:10:00.147Z. The NVD entry is currently Deferred. The source details are limited, and defenders should verify the affected scope and severity with the vendor or other trusted sources. The exploit has been released to the public, and defenders should prioritize patching or mitigating this vulnerability. Evidence limits suggest that the vulnerability is in the /omnidocs/WebApiRequestRedirection file, but further details are not available.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-02T18:16:35.777Z and has not been modified since then. The NVD entry is currently Deferred.