What is CVE-2026-72544?
An integrity verification vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to forge document audit-trail entries. The issue stems from the 'triggerevent Parse' cloud function accepting viewer identity and IP address as caller-supplied parameters without proper authentication. Users should upgrade to the latest patched version immediately.
Azərbaycanca: OpenSign (2.37.0 versiyasına qədər) audit izi qeydlərinin bütövlüyünün yoxlanılmasında boşluq aşkar edilib. Bu, autentifikasiya olunmamış uzaqdan hücumçulara 'triggerevent Parse' bulud funksiyası vasitəsilə saxta audit izi qeydləri yaratmağa imkan verir. İstifadəçilərə dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-287
FAQ1
Through which function in OpenSign is CVE-2026-72544 exploited?
This vulnerability is exploited through the 'triggerevent Parse' cloud function.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.