Junglewise Threat Intelligence

CVE-2026-72543: OpenSignLabs OpenSign insecure direct object reference in contact retrieval

CVE-2026-72543 · Severity: high · CVSS 7.5 · Published 2026-08-11

Technologies: OpenSignLabs OpenSign. Vendors: OpenSignLabs.

Executive brief

OpenSign is an open-source document signing and contract management platform. An authentication bypass flaw allows attackers to retrieve any contact record—including names, email addresses, and other personally identifiable information—without logging in. Attackers can enumerate and access the full contact database, creating a significant privacy and data breach risk.

Technical details

The vulnerability is an insecure direct object reference (IDOR) in the getcontact Parse cloud function. The function executes with master-level privileges (useMasterKey) but performs no authentication or authorization checks before returning requested contact objects. Because the function is accessible over the network and requires no credentials, an unauthenticated remote attacker can enumerate contact IDs and retrieve any record. The vulnerability affects OpenSign through version 2.37.0; patched versions or configuration mitigations should be applied.

Affected products

  • OpenSignLabs OpenSign through 2.37.0

Timeline

  • 2026-08-11: disclosed

References

Related threats