What is CVE-2026-72549?
This vulnerability in OpenSign versions up to 2.37.0 allows unauthenticated remote attackers to map any email or username to its internal user objectId via the `getUserId` cloud function, which lacks authentication. Organizations should immediately update OpenSign or enforce access control on the affected cloud function.
Azərbaycanca: Bu boşluq OpenSign-in 2.37.0 və əvvəlki versiyalarında autentifikasiya olunmamış uzaqdan hücumçuya hər hansı bir e-poçt ünvanını və ya istifadəçi adını daxili user objectId ilə əlaqələndirməyə imkan verir. Təşkilatlar dərhal OpenSign-i ən son versiyaya yeniləməli və ya `getUserId` Parse cloud funksiyasına giriş nəzarəti tətbiq etməlidir.
Related CVEs
link basis: same weakness class CWE-306
FAQ2
What product is affected by CVE-2026-72549, and which versions are vulnerable?
This vulnerability affects OpenSign versions up to and including 2.37.0.
How can CVE-2026-72549 be mitigated?
Organizations should immediately update OpenSign to the latest version or enforce access control on the `getUserId` Parse cloud function.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.