PatchSiren

OptimiDoc CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM OptimiDoc CVE published 2026-09-03

CVE-2026-15933

OptimiDoc Server (On-Premise) stores credentials for external services in cleartext, allowing authenticated administrators to view previously configured service passwords, including SMTP, FTP, Active Directory, and SharePoint credentials, via the web administration panel page source. This issue was reported by [email protected] and affects OptimiDoc Server (On-Premise). The vulnerability has a CVSS score of 6.9 [truncated]