CVE-2026-72544
Received Received - Intake

Integrity Verification Bypass in OpenSign via Parse Cloud Function

Vulnerability report for CVE-2026-72544, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-11

Assigner: 309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c

Description

An integrity verification vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to forge document audit-trail entries via the triggerevent Parse cloud function. The function accepts viewer identity and IP address as caller-supplied parameters without authentication, allowing fabrication of arbitrary audit log entries. An attacker can tamper with the legal audit trail of any signed document, undermining non-repudiation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-11
Generated
2026-08-11
AI Q&A
2026-08-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
opensignlabs opensign 2.37.0
opensignlabs opensign to 2.37.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-345 The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows unauthenticated remote attackers to forge document audit-trail entries in OpenSign through 2.37.0. The triggerevent Parse cloud function accepts viewer identity and IP address without authentication, enabling fabrication of arbitrary audit log entries. This undermines the integrity of signed document trails.

Detection Guidance

Detecting this vulnerability requires checking for unauthorized modifications to audit trails in OpenSign. Monitor logs for unexpected Parse cloud function calls with viewer identity or IP address parameters. Inspect network traffic for unauthenticated requests to the triggerevent endpoint. Verify document audit trails for inconsistencies or forged entries.

Impact Analysis

An attacker could tamper with the legal audit trail of any signed document, making it appear as if unauthorized actions were performed. This could lead to disputes over document validity, loss of trust in digital signatures, and potential legal or financial consequences if documents are falsely altered.

Compliance Impact

This vulnerability undermines non-repudiation, a key requirement for compliance with GDPR, HIPAA, and other regulations. Forged audit trails could invalidate legally required records, leading to non-compliance, legal penalties, or loss of certification for handling sensitive data.

Mitigation Strategies

Upgrade OpenSign to a version beyond 2.37.0 where the integrity verification flaw is patched. Disable or restrict access to the triggerevent Parse cloud function if not required. Implement network-level controls to block unauthorized access to the vulnerable function endpoints.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-72544. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart