PatchSiren

OpenSignLabs CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH OpenSignLabs CVE published 2026-09-16

CVE-2026-92794

OpenSign through 2.41.3 has an information disclosure vulnerability in the getDocument cloud function when one-time-password verification is disabled. This allows attackers to retrieve complete document details, including signers' information, sender identity, and valid download tokens, without authentication, by supplying a document identifier from guest signing links.

MEDIUM OpenSignLabs CVE published 2026-08-11

CVE-2026-72549

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-11T12:17:40.483Z and has not been modified since then. This information disclosure vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to map any email address or username to its internal user objectId via the getUserId Parse cloud function. The function per [truncated]

HIGH OpenSignLabs CVE published 2026-08-11

CVE-2026-72548

An information disclosure vulnerability exists in OpenSignLabs OpenSign through version 2.37.0. The vulnerability allows unauthenticated remote attackers to retrieve any organization tenant record via the gettenant Parse cloud function. This function accepts a contactId parameter and returns the full tenant record without authentication or authorization checks, enabling attackers to enumerate and disclose [truncated]

HIGH OpenSignLabs CVE published 2026-08-11

CVE-2026-72545

An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to write to any contact record via the updatecontacttour Parse cloud function. The function performs no authentication or authorization before updating the target contact record. An attacker can corrupt or overwrite contact data for any user in the system without credentials. T [truncated]

HIGH OpenSignLabs CVE published 2026-08-10

CVE-2026-72691

An executive overview of CVE-2026-72691: an authentication bypass vulnerability in OpenSignLabs opensignserver through 2.37.0 allows unauthenticated remote attackers to mint MASTER_KEY-signed file access tokens for arbitrary stored files via the getsignedurl Parse cloud function. The function skips its isAuthenticated check whenever any docId parameter is supplied, even one corresponding to no real docume [truncated]

HIGH OpenSignLabs CVE published 2026-08-10

CVE-2026-72689

A broken object-level authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to read complete contract records via the getDocument Parse cloud function. The function fetches documents using useMasterKey, bypassing the object ACL, and returns full records including sender and signer PII and a pre-signed document download URL whenever the document [truncated]

HIGH OpenSignLabs CVE published 2026-08-10

CVE-2026-72688

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-10T13:20:38.987Z and has not been modified since then. The OpenSignLabs opensignserver through 2.37.0 has a missing authentication vulnerability. The fileupload Parse cloud function mints MASTER_KEY-signed file access tokens for any caller-supplied URL without performing session checks, allowing una [truncated]