Junglewise Threat Intelligence

CVE-2026-5414: Newgen OmniDocs resource injection in WebApiRequestRedirection

CVE-2026-5414 · Severity: medium · CVSS 5.3 · Published 2026-04-02

Executive brief

Newgen OmniDocs, a document management platform, contains a security flaw that could allow unauthorized access to files. By manipulating specific document identifiers, a remote attacker can potentially view or retrieve documents they are not authorized to see. This could lead to the exposure of sensitive corporate data or personal information stored within the system.

Technical details

A vulnerability classified as CWE-99 (Improper Control of Resource Identifiers) exists in Newgen OmniDocs up to version 12.0.00. The flaw is located within the /omnidocs/WebApiRequestRedirection endpoint, where the application fails to properly validate or restrict the 'DocumentId' parameter. A remote, unauthenticated attacker can exploit this by supplying manipulated identifiers to access unauthorized resources or documents. A public proof-of-concept exploit exists, and the vendor has reportedly not responded to disclosure attempts.

Affected products

  • Newgen OmniDocs up to 12.0.00

Timeline

  • 2026-04-02: disclosed: Public disclosure via VulDB and NVD
  • 2026-04-02: advisory

References

Related threats