Executive brief
SigningHub is a digital signature and document workflow platform used to securely sign and manage legal documents. A security flaw in the mobile number verification process allows an attacker to bypass identity checks by repeatedly guessing one-time passwords (OTPs) without being blocked. This could allow an unauthorized individual to impersonate a user or verify a fraudulent mobile number, potentially compromising the integrity of the document signing process.
Technical details
The vulnerability is classified as CWE-307 (Improper Restriction of Excessive Authentication Attempts) within the mobile number verification function of SigningHub. The OTP verification endpoint fails to implement rate limiting or account lockout mechanisms after multiple failed attempts. A remote attacker can exploit this by automating a high volume of OTP guesses in rapid succession to successfully verify a mobile number without knowing the actual code. This bypasses a critical identity verification step. The issue is reported to be fixed in versions subsequent to 8.6.8.
Affected products
- Ascertia SigningHub <= 8.6.8
Timeline
- 2025-10-20: disclosed
- 2025-10-20: advisory