Junglewise Threat Intelligence

CVE-2026-5413: Newgen OmniDocs information disclosure in GetWebApiConfiguration

CVE-2026-5413 · Severity: low · CVSS 3.7 · Published 2026-04-02

Executive brief

Newgen OmniDocs, a document management platform, contains a vulnerability that could allow an unauthorized person to view sensitive configuration information. By sending a specially crafted request to the system, an attacker could potentially gain insights into internal connection details. While the attack is complex to execute, it could lead to the exposure of technical data that might be used for further attacks.

Technical details

An information disclosure vulnerability exists in Newgen OmniDocs versions up to 12.0.00 within the /omnidocs/GetWebApiConfiguration component. The vulnerability is triggered by manipulating the 'connectionDetails' argument, which leads to the exposure of sensitive information (CWE-200). The attack can be performed remotely over the network without authentication, though it is characterized by high complexity and difficult exploitation. A public exploit is reportedly available. As of the advisory date, the vendor has not responded to disclosure attempts, and no official patch has been confirmed.

Affected products

  • Newgen OmniDocs up to 12.0.00

Timeline

  • 2026-04-02: disclosed: Initial disclosure by VulDB
  • 2026-04-02: advisory: NVD publication date

References

Related threats