CVE-2026-72689: CWE-639: Authorization Bypass Through User-Controlled Key in OpenSignLabs opensignserver
A broken object-level authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to read complete contract records via the getDocument Parse cloud function. The function fetches documents using useMasterKey, bypassing the object ACL, and returns full records including sender and signer PII and a pre-signed document download URL whenever the document's IsEnableOTP flag is unset, which is the default configuration.
AI Analysis
Technical Summary
This vulnerability (CWE-639) in OpenSignLabs opensignserver through version 2.37.0 involves broken object-level authorization. The getDocument Parse cloud function improperly uses the master key (useMasterKey) to retrieve documents, ignoring object access control lists (ACLs). As a result, unauthenticated remote attackers can access full contract records, including sensitive PII and pre-signed URLs for document downloads, whenever the IsEnableOTP flag is not enabled (default configuration). This exposure compromises confidentiality of contract data without requiring authentication.
Potential Impact
An unauthenticated attacker can bypass authorization controls to access complete contract records, including sensitive personal information of senders and signers, and obtain pre-signed URLs that allow document downloads. This leads to a confidentiality breach of sensitive contract data. There is no indication of impact on integrity or availability. The vulnerability is rated high severity with a CVSS score of 7.5.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should consider enabling the IsEnableOTP flag on documents to prevent unauthorized access, as the vulnerability is exploitable only when this flag is unset (default). Monitor vendor channels for updates and apply patches promptly once released.
CVE-2026-72689: CWE-639: Authorization Bypass Through User-Controlled Key in OpenSignLabs opensignserver
Description
A broken object-level authorization vulnerability in OpenSignLabs opensignserver through 2.37.0 allows an unauthenticated remote attacker to read complete contract records via the getDocument Parse cloud function. The function fetches documents using useMasterKey, bypassing the object ACL, and returns full records including sender and signer PII and a pre-signed document download URL whenever the document's IsEnableOTP flag is unset, which is the default configuration.
CVSS v3.1
Score 7.5high
Affected software
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability (CWE-639) in OpenSignLabs opensignserver through version 2.37.0 involves broken object-level authorization. The getDocument Parse cloud function improperly uses the master key (useMasterKey) to retrieve documents, ignoring object access control lists (ACLs). As a result, unauthenticated remote attackers can access full contract records, including sensitive PII and pre-signed URLs for document downloads, whenever the IsEnableOTP flag is not enabled (default configuration). This exposure compromises confidentiality of contract data without requiring authentication.
Potential Impact
An unauthenticated attacker can bypass authorization controls to access complete contract records, including sensitive personal information of senders and signers, and obtain pre-signed URLs that allow document downloads. This leads to a confidentiality breach of sensitive contract data. There is no indication of impact on integrity or availability. The vulnerability is rated high severity with a CVSS score of 7.5.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until an official fix is available, users should consider enabling the IsEnableOTP flag on documents to prevent unauthorized access, as the vulnerability is exploitable only when this flag is unset (default). Monitor vendor channels for updates and apply patches promptly once released.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- TuranSec
- Date Reserved
- 2026-08-10T11:55:39.471Z
- Cvss Version
- 3.1
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a79c3abbf8831d539a74105
Added to database: 08/10/2026, 12:27:23 UTC
Last enriched: 08/10/2026, 12:41:28 UTC
Last updated: 08/10/2026, 16:11:54 UTC
Views: 7
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.