What is CVE-2026-72548?
An information disclosure vulnerability in OpenSignLabs OpenSign through version 2.37.0 allows unauthenticated remote attackers to retrieve any organization's tenant record via the gettenant Parse cloud function. The function accepts a contactId parameter and returns the full tenant record without requiring authentication. Users are advised to update OpenSign as soon as possible.
Azərbaycanca: OpenSign (2.37.0 versiyasına qədər) platformasında autentifikasiya olunmamış uzaqdan hücumçulara "gettenant" Parse cloud funksiyası vasitəsilə təşkilat məlumatlarını əldə etməyə imkan verən məlumat sızması zəifliyi aşkar edilib. Bu funksiya contactId parametrini qəbul edərək heç bir autentifikasiya tələb etmədən tam kirayəçi qeydini qaytarır. İstifadəçilərə OpenSign-ı mümkün qədər tez yeniləmələri tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-200
FAQ2
What type of attack does CVE-2026-72548 allow in OpenSign?
It is an information disclosure vulnerability that allows unauthenticated remote attackers to retrieve any organization's tenant record via the 'gettenant' Parse cloud function.
Which version of OpenSign is affected by CVE-2026-72548?
All versions of OpenSign up to and including version 2.37.0 are affected by this vulnerability.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.