CVE-2026-8931
Received Received - Intake
Remote Code Execution in Disig Web Signer

Publication date: 2026-06-01

Last updated on: 2026-06-01

Assigner: National Cyber Security Centre SK-CERT

Description
A critical Remote Code Execution (RCE) vulnerability exists in Disig Web Signer versions 2.0.3 through 2.5.3.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-01
Last Modified
2026-06-01
Generated
2026-06-01
AI Q&A
2026-06-01
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
disig web_signer From 2.0.3 (inc) to 2.5.3 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-94 The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?

CVE-2026-8931 is a critical Remote Code Execution (RCE) vulnerability found in older versions (2.0.3 through 2.5.3) of the Disig Web Signer application, which runs on Windows, macOS, and Linux.

This vulnerability allows an attacker to execute arbitrary code remotely, potentially compromising the affected system.

The issue was discovered by security expert Marek AlakΕ‘a from Binary House and has been fixed in version 2.5.5 of the Web Signer application.


How can this vulnerability impact me? :

This critical Remote Code Execution vulnerability can allow attackers to run malicious code on your system without your permission.

Such an exploit could lead to unauthorized access, data theft, system compromise, or further attacks within your network.

Because the vulnerability affects a widely used digital signing application, it poses a significant security risk to users who have not updated to the fixed version.

Immediate updating to version 2.5.5 is strongly recommended to mitigate these risks.


How can this vulnerability be detected on my network or system? Can you suggest some commands?

This vulnerability affects Disig Web Signer versions 2.0.3 through 2.5.3. Detection can be done by verifying the installed version of the Web Signer application on your system.

To detect if your system is vulnerable, check the version of the Web Signer application installed on your Windows, macOS, or Linux system. If the version is between 2.0.3 and 2.5.3 inclusive, the system is vulnerable.

Suggested commands to check the installed version depend on the operating system:

  • On Windows, check the application version via the Control Panel's Programs and Features or by right-clicking the Web Signer executable and viewing Properties > Details.
  • On macOS, use the Finder to locate the Web Signer app, then use 'Get Info' to see the version, or run a command in Terminal such as: `/Applications/WebSigner.app/Contents/MacOS/WebSigner --version` if supported.
  • On Linux, check the version by running a command like: `websigner --version` or check the package manager, e.g., `dpkg -l | grep websigner` or `rpm -qa | grep websigner`.

Since the vulnerability is specific to versions 2.0.3 through 2.5.3, confirming the installed version within this range indicates exposure.


What immediate steps should I take to mitigate this vulnerability?

The primary and immediate mitigation step is to update the Disig Web Signer application to the latest version, 2.5.5, which contains the fix for this critical vulnerability.

Users can update either through an automatic prompt from the application or manually by checking for updates via the system tray icon.

Alternatively, updated installation packages are available for download on the official Disig website, which can be used to perform a manual update.

Prompt action is strongly recommended to ensure protection against potential exploitation of this critical Remote Code Execution vulnerability.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart