PatchSiren

OpenSignLabs CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH OpenSignLabs CVE published 2026-08-10

CVE-2026-72691

An executive overview of CVE-2026-72691: an authentication bypass vulnerability in OpenSignLabs opensignserver through 2.37.0 allows unauthenticated remote attackers to mint MASTER_KEY-signed file access tokens for arbitrary stored files via the getsignedurl Parse cloud function. The function skips its isAuthenticated check whenever any docId parameter is supplied, even one corresponding to no real docume [truncated]

HIGH OpenSignLabs CVE published 2026-08-10

CVE-2026-72689

A broken object-level authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to read complete contract records via the getDocument Parse cloud function. The function fetches documents using useMasterKey, bypassing the object ACL, and returns full records including sender and signer PII and a pre-signed document download URL whenever the document [truncated]

HIGH OpenSignLabs CVE published 2026-08-10

CVE-2026-72688

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-10T13:20:38.987Z and has not been modified since then. The OpenSignLabs opensignserver through 2.37.0 has a missing authentication vulnerability. The fileupload Parse cloud function mints MASTER_KEY-signed file access tokens for any caller-supplied URL without performing session checks, allowing una [truncated]