Junglewise Threat Intelligence

CVE-2026-25826: Keyfactor SignServer file content exposure in PKCS11CryptoToken

CVE-2026-25826 · Severity: medium · CVSS 4.9 · Published 2026-09-15

Executive brief

Keyfactor SignServer is an enterprise software solution used for cryptographic signing and digital certificate management. A vulnerability in its PKCS11CryptoToken component allows users with administrative access to inadvertently expose sensitive file contents by misconfiguring the ATTRIBUTESFILE attribute, which causes error messages containing file data to be logged. An attacker with both SignServer admin privileges and access to application server logs could read files accessible to the local JBoss user, potentially compromising cryptographic keys or other sensitive data.

Technical details

The vulnerability is an information disclosure flaw in the PKCS11CryptoToken component of SignServer. When the ATTRIBUTESFILE attribute is set to a readable file that is not a valid PKCS11 attributes file, an error is thrown that logs the full contents of the file to the application server log. The attack requires two preconditions: SignServer admin access (to configure the token) and ability to read application server logs (feasible if remote syslog is configured). An attacker cannot directly trigger file reads but must rely on administrator misconfiguration or social engineering. The vulnerability was fixed in SignServer 7.6.0 and later versions.

Affected products

  • Keyfactor SignServer before 7.6.0

Timeline

  • 2026-09-15: disclosed: CVE-2026-25826 published
  • 2026: patched: Fixed in SignServer 7.6.0

References

Related threats