CVE-2026-72543: CWE-639: Authorization Bypass Through User-Controlled Key in OpenSignLabs OpenSign
An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to retrieve any contact record via the getcontact Parse cloud function. The function executes with useMasterKey and performs no authentication or authorization checks before returning the requested contact object. An attacker can enumerate and read all contact records including personally identifiable information without credentials.
AI Analysis
Technical Summary
The vulnerability is an insecure direct object reference (CWE-639) in OpenSignLabs OpenSign through version 2.37.0. The getcontact Parse cloud function executes with useMasterKey privileges but does not perform any authentication or authorization checks before returning requested contact objects. As a result, unauthenticated remote attackers can enumerate and read all contact records, exposing sensitive personal data. No patch or official remediation level is currently documented. The CVSS 3.1 base score is 7.5, reflecting high severity with network attack vector, low attack complexity, no privileges required, no user interaction, and high confidentiality impact.
Potential Impact
Attackers can remotely and without authentication access all contact records stored by OpenSign, including personally identifiable information. This leads to a significant confidentiality breach. There is no impact on integrity or availability reported. The exposure of sensitive user data can result in privacy violations and potential misuse of personal information.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict access to the getcontact function or disable it if possible. Implement additional authentication and authorization controls on cloud functions that handle sensitive data to prevent unauthorized access.
CVE-2026-72543: CWE-639: Authorization Bypass Through User-Controlled Key in OpenSignLabs OpenSign
Description
An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to retrieve any contact record via the getcontact Parse cloud function. The function executes with useMasterKey and performs no authentication or authorization checks before returning the requested contact object. An attacker can enumerate and read all contact records including personally identifiable information without credentials.
CVSS v3.1
Score 7.5high
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability is an insecure direct object reference (CWE-639) in OpenSignLabs OpenSign through version 2.37.0. The getcontact Parse cloud function executes with useMasterKey privileges but does not perform any authentication or authorization checks before returning requested contact objects. As a result, unauthenticated remote attackers can enumerate and read all contact records, exposing sensitive personal data. No patch or official remediation level is currently documented. The CVSS 3.1 base score is 7.5, reflecting high severity with network attack vector, low attack complexity, no privileges required, no user interaction, and high confidentiality impact.
Potential Impact
Attackers can remotely and without authentication access all contact records stored by OpenSign, including personally identifiable information. This leads to a significant confidentiality breach. There is no impact on integrity or availability reported. The exposure of sensitive user data can result in privacy violations and potential misuse of personal information.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, restrict access to the getcontact function or disable it if possible. Implement additional authentication and authorization controls on cloud functions that handle sensitive data to prevent unauthorized access.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- TuranSec
- Date Reserved
- 2026-08-10T10:32:49.080Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a7b0703bf8831d539a0cc26
Added to database: 08/11/2026, 11:26:59 UTC
Last enriched: 08/11/2026, 11:43:35 UTC
Last updated: 08/11/2026, 18:43:13 UTC
Views: 5
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.