Junglewise Threat Intelligence

CVE-2026-8931: Disig Web Signer Remote Code Execution

CVE-2026-8931 · Severity: info · CVSS 9.4 · Published 2026-06-01

Executive brief

Disig Web Signer, an application used for creating electronic signatures on Windows, macOS, and Linux, contains a critical security vulnerability. An attacker could exploit this flaw to remotely execute unauthorized code on a user's computer. This could lead to a total compromise of the system, including the theft of sensitive data or unauthorized signing of documents.

Technical details

A critical Remote Code Execution (RCE) vulnerability exists in Disig Web Signer versions 2.0.3 through 2.5.3. The vulnerability allows for high-impact compromise of confidentiality, integrity, and availability (CVSS 9.4). While specific root cause details (such as the exact CWE) are not fully detailed in the advisory, the CVSS vector indicates a network attack vector requiring passive user interaction (UI:P). The flaw was addressed in version 2.5.5, which changed how the application communicates with the QES Portal, moving toward a WebSocket interface that does not require browser extensions. Security researcher Marek Alakša is credited with the discovery.

Affected products

  • Disig Web Signer 2.0.3 - 2.5.3

Timeline

  • 2026-05-11: patched: Version 2.5.5 released to fix the vulnerability
  • 2026-06-01: disclosed: CVE-2026-8931 published

References