Junglewise Threat Intelligence

CVE-2026-25825: Keyfactor SignServer arbitrary file write in SignerStatusReportWorker

CVE-2026-25825 · Severity: low · CVSS 2.7 · Published 2026-09-15

Executive brief

Keyfactor SignServer is a digital signing platform used to manage and apply digital signatures to documents and transactions. An administrator with access to the SignerStatusReportWorker configuration can write arbitrary files to any location on the server filesystem, potentially overwriting critical application or system files. This could lead to service disruption, data loss, or unauthorized code execution depending on which files are overwritten.

Technical details

A path traversal vulnerability exists in SignerStatusReportWorker in Keyfactor SignServer versions before 7.6.0, where the output file path for status reports is not properly validated. An authenticated administrator can specify any filesystem path—including paths with directory traversal sequences or absolute paths—to write the report file to arbitrary locations. The vulnerability requires administrator access and could result in overwriting files owned by the JBoss application server process, potentially compromising application integrity or availability. The fix is available in version 7.6.0 and later.

Affected products

  • Keyfactor SignServer before 7.6.0

Timeline

  • 2026-09-15: disclosed

References

Related threats