CVE-2026-25826
Received Received - Intake

Information Disclosure in Keyfactor SignServer

Vulnerability report for CVE-2026-25826, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-15

Last updated on: 2026-09-15

Assigner: MITRE

Description

An issue was discovered in Keyfactor SignServer before 7.6.0. The attribute ATTRIBUTESFILE in PKCS11CryptoToken can be set to a readable file but not an accepted file (i.e., recognized with attributes). In this case, an error is thrown which - together with the error - also prints the content of the file to the application server log. This gives a user that has both SignServer admin access and access to read the output of the server log (i.e., if remote syslog shipping is configured), the possibility to read the content of files accessible by the local user JBoss.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-15
Last Modified
2026-09-15
Generated
2026-09-15
AI Q&A
2026-09-15
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
keyfactor signserver to 7.6.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-25826 is a vulnerability in Keyfactor SignServer versions before 7.6.0. It occurs when the ATTRIBUTESFILE setting in PKCS11CryptoToken is configured to point to a readable file that is not a valid attributes file. This causes an error that logs the file's contents to the application server log. An attacker with both admin access to SignServer and access to the server logs could exploit this to read sensitive files accessible by the JBoss user.

Detection Guidance

Check SignServer application server logs for error messages containing file contents when ATTRIBUTESFILE is set to an unrecognized file. Look for entries where errors expose sensitive data due to improper attribute handling.

Impact Analysis

This vulnerability allows an authorized admin with log access to read sensitive files on the server. If remote syslog shipping is enabled, an attacker could remotely access these logs and obtain confidential information such as configuration files, credentials, or other sensitive data stored on the system.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, potentially violating compliance requirements under GDPR, HIPAA, or other regulations that mandate protection of personal or health information. Exposure of such data may result in legal penalties, reputational damage, and loss of trust.

Mitigation Strategies

Upgrade SignServer to version 7.6.0 or later to address the vulnerability. Ensure only authorized administrators have access to server logs to prevent unauthorized exposure of sensitive file contents.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-25826. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart