What is CVE-2026-71247?
CVE-2026-71247 is a critical privilege escalation vulnerability in Documenso's live signing UI. It allows a recipient with the ASSISTANT role to complete Signature fields belonging to other higher-order recipients within the same envelope, leading to potential document forgery. Users should immediately update to the latest patched version of Documenso.
Azərbaycanca: CVE-2026-71247, Documenso elektron imza platformasında tapılan kritik bir səlahiyyət yüksəltmə zəifliyidir. Bu boşluq "ASSISTANT" roluna malik istifadəçiyə eyni envelope daxilində digər imzaçıların imza sahələrini (Signature) ələ keçirib tamamlamağa imkan verir. Bu zəiflikdən qorunmaq üçün Documenso-nun ən son versiyasına yeniləmə aparılmalıdır.
Related CVEs
link basis: same weakness class CWE-269
FAQ2
In which platform was CVE-2026-71247 discovered?
This vulnerability was discovered in the Documenso electronic signature platform.
What can an attacker achieve by exploiting CVE-2026-71247 and through which role?
An attacker with the ASSISTANT role can complete Signature fields belonging to higher-order recipients within the same envelope.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.