AUGUST 16, 2026
Live Feed
Back to database
Case File

CVE-2026-72545

HIGH · CVSS 7.5 EPSS 0.40% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-11 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

OpenSignLabs OpenSign versions up to 2.37.0 are vulnerable due to an insecure direct object reference that permits unauthenticated remote attackers to modify any contact record through the updatecontacttour Parse cloud function, which lacks proper authentication and authorization checks. This vulnerability allows attackers to corrupt or overwrite contact data for any user, posing significant risks to data integrity and privacy. Organizations using this software should prioritize patching this vulnerability to prevent unauthorized data manipulation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-72545
Severity
HIGH
CVSS
7.5
EPSS
0.40%

Original NVD Description

An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to write to any contact record via the updatecontacttour Parse cloud function. The function performs no authentication or authorization before updating the target contact record. An attacker can corrupt or overwrite contact data for any user in the system without credentials.