CVE-2026-57917
Received Received - Intake

XML External Entity Injection in proCertum SmartSign

Vulnerability report for CVE-2026-57917, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-27

Last updated on: 2026-07-27

Assigner: CERT.PL

Description

proCertum SmartSign parses external XML entities from arbitrary crafted signature files, enabling SSRF and potentially allowing the reading of local files, depending on the parser's configuration. The XML External Entity (XXE) vulnerability is triggered simply by previewing a file in the file selection window, before the victim clicks “Open”. This issue was fixed in version 9.4.3.90.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-27
Last Modified
2026-07-27
Generated
2026-07-27
AI Q&A
2026-07-27
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
procertum smartsign 9.4.3.90
asseco procertum_smartsign 9.4.3.90
asseco procertum_smartsign to 9.4.3.90 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-611 The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an XML External Entity (XXE) vulnerability in proCertum SmartSign. It allows parsing of external XML entities from crafted signature files, which can lead to Server-Side Request Forgery (SSRF) and potentially local file reads. The issue is triggered just by previewing a file in the selection window before opening it.

Detection Guidance

Detection involves checking for proCertum SmartSign versions prior to 9.4.3.90. Inspect installed software versions and monitor for unusual network activity or file access patterns during file preview operations.

Impact Analysis

An attacker could exploit this to make unauthorized requests to internal systems (SSRF) or read sensitive files on your system, depending on the XML parser configuration. This could lead to data breaches or unauthorized access to internal resources.

Compliance Impact

The XXE vulnerability in proCertum SmartSign could potentially lead to unauthorized access to local files or internal systems, which may compromise data confidentiality. This could violate GDPR's data protection requirements if personal data is exposed, and HIPAA's safeguards for protected health information if such data is involved.

Mitigation Strategies

Update proCertum SmartSign to version 9.4.3.90 or later immediately. Disable XML external entity processing in the application if possible and restrict file preview capabilities until the update is applied.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-57917. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart