What is CVE-2026-57916?
CVE-2026-57916: proCertum SmartSign opens Certificate Practice Statement (CPS) URI without schema validation. An attacker can craft a malicious certificate with a CPS URI pointing to a local executable or any URL, and when the victim opens the signed document, arbitrary code execution may occur. Affected users should immediately update proCertum SmartSign to the latest version.
Azərbaycanca: CVE-2026-57916: proCertum SmartSign tətbiqi Sertifikat Təcrübə Bəyanatı (CPS) URI-ni sxem yoxlaması olmadan açır. Təcavüzkar yerli icra edilə bilən fayla və ya hər hansı bir URL-ə yönəlmiş saxta sertifikat hazırlayıb sənəd imzalaya bilər, qurban sənədi açdıqda isə ixtiyari kod icrası baş verə bilər. Təsirə məruz qalan istifadəçilər dərhal proCertum SmartSign proqramını ən son versiyaya yeniləməlidir.
FAQ2
How can CVE-2026-57916 be exploited in proCertum SmartSign?
An attacker can craft a malicious certificate with a CPS URI pointing to a local executable or any URL and sign a document with it. When the victim opens the document, proCertum SmartSign opens the URI without schema validation, which may lead to arbitrary code execution.
What should I do to protect against this vulnerability?
Affected users should immediately update proCertum SmartSign to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.