Junglewise Threat Intelligence

CVE-2025-56219: Ascertia SigningHub improper access control in Add User API

CVE-2025-56219 · Severity: high · CVSS 7.1 · Published 2025-10-20

Technologies: Ascertia Signinghub. Vendors: Ascertia.

Executive brief

SigningHub is a digital signature and document workflow platform used to manage legally binding electronic signatures. A security flaw in the user management system allows an attacker to rapidly create an unlimited number of new user accounts. This can overwhelm the system's database and storage, potentially leading to a complete service outage or significant performance degradation.

Technical details

An improper access control vulnerability exists in the 'Add User' API of Ascertia SigningHub versions up to and including 8.6.8. The affected component lacks rate limiting or throttling mechanisms, allowing an authenticated attacker to automate the creation of a large volume of user accounts. This can result in database bloating and resource exhaustion, ultimately causing a Denial of Service (DoS) condition. The vulnerability is triggered via network requests to the API; while the CVSS vector indicates low privileges are required, the lack of registration controls effectively allows for automated exploitation. A fix is available in versions subsequent to 8.6.8.

Affected products

  • Ascertia SigningHub <= 8.6.8

Timeline

  • 2025-10-20: disclosed
  • 2025-10-20: advisory

References

Related threats