AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-72544

HIGH · CVSS 7.5 EPSS 0.20% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

OpenSignLabs OpenSign versions up to 2.37.0 are vulnerable to an integrity verification flaw that permits unauthenticated remote attackers to manipulate document audit-trail entries through the triggerevent Parse cloud function. This vulnerability enables the fabrication of arbitrary audit log entries, compromising the integrity and non-repudiation of signed documents. Organizations utilizing OpenSign for document management should prioritize patching this vulnerability to protect against potential legal and compliance ramifications.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-72544
Severity
HIGH
CVSS
7.5
EPSS
0.20%

Original NVD Description

An integrity verification vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to forge document audit-trail entries via the triggerevent Parse cloud function. The function accepts viewer identity and IP address as caller-supplied parameters without authentication, allowing fabrication of arbitrary audit log entries. An attacker can tamper with the legal audit trail of any signed document, undermining non-repudiation.