MEDIUM
OptimiDoc
CVE published 2026-09-03
CVE-2026-15933
OptimiDoc Server (On-Premise) stores credentials for external services in cleartext, allowing authenticated administrators to view previously configured service passwords, including SMTP, FTP, Active Directory, and SharePoint credentials, via the web administration panel page source. This issue was reported by [email protected] and affects OptimiDoc Server (On-Premise). The vulnerability has a CVSS score of 6.9 [truncated]