Executive brief
Documenso is an open-source document signing platform similar to DocuSign. The application fails to properly restrict access to PDF files, allowing low-privilege users to view restricted documents belonging to their team or even from other tenants. An attacker can exploit missing validation checks to read confidential documents they should not have access to.
Technical details
The vulnerability is an access control failure in the PDF-serving endpoint that does not validate document visibility settings or ownership before serving files. The root cause is missing ownership validation on document data identifiers in the files.helpers.ts component. Attackers with low privileges (authenticated users) can craft requests to bypass these checks and retrieve restricted documents within their team or across tenant boundaries. The attack requires network access to the application and user authentication, but no additional user interaction. An attacker can achieve unauthorized document disclosure affecting confidentiality.
Affected products
- Documenso Documenso 2.17.0
Timeline
- 2026-09-04: disclosed