Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://github.com/OpenSignLabs/OpenSign |
|
Tue, 11 Aug 2026 13:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Aug 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An integrity verification vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to forge document audit-trail entries via the triggerevent Parse cloud function. The function accepts viewer identity and IP address as caller-supplied parameters without authentication, allowing fabrication of arbitrary audit log entries. An attacker can tamper with the legal audit trail of any signed document, undermining non-repudiation. | |
| Title | OpenSignLabs OpenSign - Insufficient Verification of Data Authenticity | |
| Weaknesses | CWE-345 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: TuranSec
Published:
Updated: 2026-08-11T12:24:54.943Z
Reserved: 2026-08-10T10:32:49.081Z
Link: CVE-2026-72544
Updated: 2026-08-11T12:24:45.355Z
Status : Received
Published: 2026-08-11T12:17:39.847
Modified: 2026-08-11T13:19:03.030
Link: CVE-2026-72544
No data.
OpenCVE Enrichment
Updated: 2026-08-11T17:15:06Z
-
CWE-345
Insufficient Verification of Data Authenticity