PatchSiren

OpnForm CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL OpnForm CVE published 2026-08-17

CVE-2026-75106

CVE-2026-75106 debrief based on the supplied source corpus. The CVE record was published on 2026-08-17T21:16:49.610Z and has not been modified since then. The NVD entry is currently Deferred. The OpnForm application derives editable-submission secrets from sequential row identifiers using Hashids with an empty default salt, allowing unauthenticated attackers to compute hashes for any submission and potent [truncated]