Executive brief
Disig Web Signer, an application used for creating electronic signatures on Windows, macOS, and Linux, contains a critical security vulnerability. An attacker could exploit this flaw to remotely execute unauthorized code on a user's computer. This could lead to a total compromise of the system, including the theft of sensitive data or unauthorized signing of documents.
Technical details
A critical Remote Code Execution (RCE) vulnerability exists in Disig Web Signer versions 2.0.3 through 2.5.3. The vulnerability allows for high-impact compromise of confidentiality, integrity, and availability (CVSS 9.4). While specific root cause details (such as the exact CWE) are not fully detailed in the advisory, the CVSS vector indicates a network attack vector requiring passive user interaction (UI:P). The flaw was addressed in version 2.5.5, which changed how the application communicates with the QES Portal, moving toward a WebSocket interface that does not require browser extensions. Security researcher Marek Alakša is credited with the discovery.
Affected products
- Disig Web Signer 2.0.3 - 2.5.3
Timeline
- 2026-05-11: patched: Version 2.5.5 released to fix the vulnerability
- 2026-06-01: disclosed: CVE-2026-8931 published
References
- https://download.disigcdn.sk/cdn/products/websigner2/changelog.en.txt
- https://download.disigcdn.sk/cdn/products/websigner2/changelog.sk.txt
- https://qesportal.sk/Portal/en/Info/News
- https://qesportal.sk/Portal/sk/Info/News
- https://www.disig.sk/en/news/important-update-of-the-web-signer-application/
- https://www.disig.sk/sk/aktuality/dolezita-aktualizacia-aplikacie-web-signer/