PatchSiren cyber security CVE debrief
CVE-2026-72689 OpenSignLabs CVE debrief
A broken object-level authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to read complete contract records via the getDocument Parse cloud function. The function fetches documents using useMasterKey, bypassing the object ACL, and returns full records including sender and signer PII and a pre-signed document download URL whenever the document's IsEnableOTP flag is unset, which is the default configuration. This vulnerability has significant technical impact as it allows unauthorized access to sensitive contract records. Organizations using OpenSignLabs opensignserver through 2.37.0 should prioritize verifying their inventory, checking for compensating controls, and monitoring for suspicious activity. The vulnerability's high CVSS score of 7.5 indicates a significant risk to affected systems and data, emphasizing the need for prompt action to mitigate the vulnerability and prevent potential exploitation.
- Vendor
- OpenSignLabs
- Product
- opensignserver
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-08-10
- Original CVE updated
- 2026-08-26
- Advisory published
- 2026-08-10
- Advisory updated
- 2026-08-26
Who should care
Organizations using OpenSignLabs opensignserver through 2.37.0 should be aware of this vulnerability and take necessary actions to protect their systems and data. This includes verifying their inventory, checking for compensating controls, and monitoring for suspicious activity. Security teams and vulnerability management teams should prioritize this vulnerability due to its high severity and potential impact on sensitive contract records. Additionally, operators and platform administrators should review their configurations and ensure that proper authorization controls are in place to prevent unauthorized access to contract records. This vulnerability may require immediate attention to prevent potential exploitation and protect sensitive information. The vulnerability's high CVSS score of 7.5 indicates a significant risk to affected systems and data, emphasizing the need for prompt action to mitigate the vulnerability and prevent potential exploitation. The vulnerability affects OpenSignLabs opensignserver through version 2.37.0, and organizations using this version or earlier should take immediate action to protect their systems and data. The vulnerability's impact on security teams and vulnerability management teams is significant, as it requires immediate attention and action to prevent potential exploitation and protect sensitive information. The vulnerability's impact on operators and platform administrators is also significant, as it requires review of configurations and ensuring proper authorization controls are in place to prevent unauthorized access to contract records. The vulnerability's high severity and potential impact on sensitive contract records emphasize the need for prompt action to mitigate the vulnerability and prevent potential exploitation. The vulnerability affects a wide range of systems and data, and organizations should prioritize this vulnerability to prevent potential exploitation and protect sensitive information. The vulnerability's CVSS score of 7.5 indicates a significant risk to affected systems and data, emphasizing the need for prompt action to mitigate the vulnerability and prevent potential exploitation. The vulnerability's
Technical summary
A broken object-level authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to read complete contract records via the getDocument Parse cloud function. The function fetches documents using useMasterKey, bypassing the object ACL, and returns full records including sender and signer PII and a pre-signed document download URL whenever the document's IsEnableOTP flag is unset, which is the default configuration. This vulnerability has significant technical impact as it allows unauthorized access to sensitive contract records.
Defensive priority
Organizations using OpenSignLabs opensignserver through 2.37.0 should prioritize verifying their inventory, checking for compensating controls, and monitoring for suspicious activity.
Recommended defensive actions
- Verify inventory of OpenSignLabs opensignserver instances
- Check for compensating controls
- Monitor for suspicious activity
- Review configurations to ensure proper authorization controls are in place
- Track exceptions and retest remediated assets
- Plan vendor-supported updates or mitigations through normal change control
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE description indicates a broken object-level authorization vulnerability in OpenSignLabs opensignserver through 2.37.0, allowing unauthenticated remote attackers to read complete contract records via the getDocument Parse cloud function. Evidence is limited to CVE and NVD records. The vulnerability has a CVSS score of 7.5 and is considered HIGH severity. Organizations should verify their inventory, check for compensating controls, and monitor for suspicious activity.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-72689 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-72689
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-72689 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-72689
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/OpenSignLabs/OpenSign
309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.