Junglewise Threat Intelligence

CVE-2026-82472: Documenso unauthenticated PDF file upload

CVE-2026-82472 · Severity: high · CVSS 7.5 · Published 2026-08-29

Technologies: Documenso. Vendors: Documenso.

Executive brief

Documenso is an open-source document signing platform used as an alternative to DocuSign. The application's PDF upload endpoint lacks authentication checks, allowing unauthenticated attackers to upload arbitrary PDF files without logging in. An attacker can upload files indefinitely to exhaust server storage, degrade performance, or fill the database with orphaned records, potentially leading to service disruption.

Technical details

The vulnerability is an authentication bypass in the `/api/files/upload-pdf` endpoint in Documenso before version 2.13.0. The endpoint fails to validate authentication tokens, session cookies, or API credentials before processing file uploads. An attacker can send POST requests to this endpoint with arbitrary PDF files from any network location without pre-authentication. This allows unrestricted file uploads that exhaust storage resources and pollute the database with unlinked document records, resulting in denial of service. The fix is available in version 2.13.0 and later.

Affected products

  • Documenso Documenso before 2.13.0

Timeline

  • 2026-08-29: disclosed
  • 2026: patched: Fixed in version 2.13.0

References

Related threats