CVE-2026-72549
Received Received - Intake

Information Disclosure in OpenSignLabs OpenSign

Vulnerability report for CVE-2026-72549, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-11

Assigner: 309f9ea4-e3e9-4c6c-b79d-e8eb01244f2c

Description

An information disclosure vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to map any email address or username to its internal user objectId via the getUserId Parse cloud function. The function performs no authentication before resolving and returning the internal identifier. An attacker can use this to enumerate user accounts and target subsequent attacks.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-11
Generated
2026-08-11
AI Q&A
2026-08-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
opensignlabs opensign 2.37.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-200 The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability allows unauthenticated remote attackers to map any email address or username to its internal user objectId via the getUserId Parse cloud function in OpenSign through 2.37.0. The function lacks authentication checks before resolving and returning the internal identifier, enabling attackers to enumerate user accounts.

Detection Guidance

To detect this vulnerability, you can test if the getUserId Parse cloud function in OpenSign 2.37.0 or earlier allows unauthenticated requests to resolve email addresses or usernames to internal user IDs. Send a GET or POST request to the vulnerable endpoint with a test email or username and check if it returns an internal user objectId without authentication.

Impact Analysis

Attackers can use this to identify valid user accounts, which may lead to targeted phishing, brute force attacks, or other social engineering attempts. It exposes internal user identifiers that could be used in further exploits.

Compliance Impact

This vulnerability may violate data protection requirements under GDPR and HIPAA by exposing personal identifiers without proper access controls. It undermines user privacy and could lead to non-compliance with security and privacy standards.

Mitigation Strategies

Immediately update OpenSign to the latest version beyond 2.37.0, as the vulnerability is patched in newer releases. If an update is not available, disable the getUserId Parse cloud function or restrict access to authenticated users only. Review server logs for suspicious requests attempting to enumerate user accounts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-72549. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart