What is CVE-2026-72543?
An Insecure Direct Object Reference vulnerability in OpenSignLabs OpenSign up to version 2.37.0 allows unauthenticated remote attackers to retrieve any contact record via the `getcontact` Parse cloud function. This occurs because the function uses `useMasterKey` without proper authentication or authorization checks. Immediate patching is strongly recommended.
Azərbaycanca: OpenSign 2.37.0 versiyasına qədər olan OpenSignLabs məhsulunda Insecure Direct Object Reference zəifliyi aşkarlanıb. Bu boşluq autentifikasiya olunmamış uzaqdan hücum edənə `getcontact` Parse cloud funksiyası vasitəsilə istənilən kontakt qeydini əldə etməyə imkan verir. Dərhal müvafiq təhlükəsizlik yeniləməsini tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862; shared vendor: OpenSignLabs
FAQ2
Which versions of OpenSign are affected by CVE-2026-72543?
This vulnerability affects all versions of OpenSign up to version 2.37.0.
What data can an attacker access by exploiting CVE-2026-72543?
An unauthenticated remote attacker can retrieve any contact record via the `getcontact` Parse cloud function.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.