Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-72544

HIGH NVD
CVSS Score 7.5
Severity HIGH
Published Aug 11, 2026
Vendor unknown

Description

An integrity verification vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to forge document audit-trail entries via the triggerevent Parse cloud function. The function accepts viewer identity and IP address as caller-supplied parameters without authentication, allowing fabrication of arbitrary audit log entries. An attacker can tamper with the legal audit trail of any signed document, undermining non-repudiation.

References