Executive brief
SigningHub is a digital signature and document workflow platform used to manage legally binding electronic signatures. A security flaw in the user management system allows an attacker to rapidly create an unlimited number of new user accounts. This can overwhelm the system's database and storage, potentially leading to a complete service outage or significant performance degradation.
Technical details
An improper access control vulnerability exists in the 'Add User' API of Ascertia SigningHub versions up to and including 8.6.8. The affected component lacks rate limiting or throttling mechanisms, allowing an authenticated attacker to automate the creation of a large volume of user accounts. This can result in database bloating and resource exhaustion, ultimately causing a Denial of Service (DoS) condition. The vulnerability is triggered via network requests to the API; while the CVSS vector indicates low privileges are required, the lack of registration controls effectively allows for automated exploitation. A fix is available in versions subsequent to 8.6.8.
Affected products
- Ascertia SigningHub <= 8.6.8
Timeline
- 2025-10-20: disclosed
- 2025-10-20: advisory