Junglewise Threat Intelligence

CVE-2026-72545: OpenSignLabs OpenSign insecure direct object reference in contact update

CVE-2026-72545 · Severity: high · CVSS 7.5 · Published 2026-08-11

Technologies: OpenSignLabs OpenSign. Vendors: OpenSignLabs.

Executive brief

OpenSign is an open-source document signing platform that serves as an alternative to DocuSign. A vulnerability allows attackers to modify any user's contact information without authentication, potentially corrupting data, impersonating users, or disrupting service for all users in the system.

Technical details

An insecure direct object reference (IDOR) vulnerability exists in the updatecontacttour Parse cloud function in OpenSign through version 2.37.0. The function fails to perform authentication or authorization checks before updating contact records, allowing unauthenticated remote attackers to modify any contact record by directly specifying the target object ID. An attacker can corrupt, overwrite, or delete contact data for arbitrary users without requiring credentials or valid authentication tokens, potentially enabling account hijacking or data manipulation attacks.

Affected products

  • OpenSignLabs OpenSign through 2.37.0

Timeline

  • 2026-08-11: disclosed

References

Related threats