CVE-2026-15933
Received Received - Intake

OptimiDoc Server Cleartext Credential Exposure via Web Panel

Vulnerability report for CVE-2026-15933, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-03

Last updated on: 2026-09-03

Assigner: CERT.PL

Description

OptimiDoc Server (On-Premise) stores credentials for external services in cleartext. An authenticated administrator can view previously configured service passwords, including SMTP, FTP (for scan delivery), Active Directory (for user list import), and SharePoint credentials, in cleartext via the web administration panel page source, allowing exposure of sensitive third-party authentication data. This issue was fixed in versionΒ 26.08

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-03
Last Modified
2026-09-03
Generated
2026-09-03
AI Q&A
2026-09-03
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
optimidoc server 26.08

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-256 The product stores a password in plaintext within resources such as memory or files.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

OptimiDoc Server (On-Premise) stores credentials for external services like SMTP, FTP, Active Directory, and SharePoint in plaintext. An authenticated administrator can view these passwords by inspecting the web administration panel's page source, exposing sensitive third-party authentication data.

Detection Guidance

Check if OptimiDoc Server version is below 26.08 by inspecting the web interface or server logs. Inspect the page source of the web administration panel for plaintext credentials in HTML comments or form fields after logging in as an administrator.

Impact Analysis

This vulnerability allows attackers with administrative access to steal credentials for external services, potentially leading to unauthorized access to email systems, file transfers, user directories, or document repositories. It could enable further attacks on connected systems.

Compliance Impact

This vulnerability likely violates compliance requirements for data protection and confidentiality, such as GDPR (data breach risks) and HIPAA (exposure of authentication credentials). It may lead to regulatory penalties due to unauthorized access to sensitive data.

Mitigation Strategies

Upgrade OptimiDoc Server to version 26.08 or later immediately. Review and rotate all exposed credentials for SMTP, FTP, Active Directory, and SharePoint services. Restrict administrator access to the web panel until the upgrade is complete.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-15933. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart