Junglewise Threat Intelligence

CVE-2026-72548: OpenSignLabs OpenSign information disclosure in gettenant function

CVE-2026-72548 · Severity: high · CVSS 7.5 · Published 2026-08-11

Technologies: OpenSignLabs OpenSign. Vendors: OpenSignLabs.

Executive brief

OpenSign is an open-source document signing platform offering DocuSign-like functionality for enterprises. A flaw in the gettenant cloud function allows attackers to retrieve any organization's tenant configuration data—including sensitive settings and customer details—without authentication, potentially exposing business information and facilitating further attacks on organizations using the platform.

Technical details

The vulnerability is an unauthenticated information disclosure in the gettenant Parse cloud function within OpenSignLabs OpenSign through version 2.37.0. The function accepts a contactId parameter and returns complete tenant records without verifying the caller's identity or authorization to access that data. An attacker can enumerate contactId values and retrieve full tenant configuration for any organization in the system over the network. This allows exposure of sensitive organizational data such as tenant settings, API keys, or other configuration details that could be leveraged for further compromise.

Affected products

  • OpenSignLabs OpenSign through 2.37.0

Timeline

  • 2026-08-11: disclosed

References

Related threats