What is CVE-2026-75106?
OpnForm generates editable-submission secrets using Hashids with sequential row IDs and an empty default salt, allowing unauthenticated attackers to compute hashes for any submission. This enables unauthorized reading or overwriting of respondents' full submission data through exposed endpoints. Affected users should update OpnForm or disable the editable-submission feature immediately.
Azərbaycanca: OpnForm platformasında "editable-submission" sirrləri, ardıcıl sıra identifikatorlarından və boş "salt" ilə Hashids istifadə edərək yaradılır. Bu boşluq autentifikasiya olunmamış hücumçulara istənilən təqdimat məlumatı üçün heşləri hesablamağa imkan verir, nəticədə həssas məlumatları oxuya və ya dəyişdirə bilərlər. Təsirə məruz qalan istifadəçilər dərhal platformanı yeniləməli və ya müvəqqəti olaraq "editable-submission" funksiyasını deaktiv etməlidir.
Related CVEs
link basis: same weakness class CWE-1188
FAQ2
What mechanism in OpnForm allows CVE-2026-75106 to compromise editable-submission secrets?
This vulnerability occurs because the editable-submission secrets are generated using Hashids with sequential row IDs and an empty default salt. Unauthenticated attackers can exploit this weakness to compute hashes for any submission.
What are the consequences of exploiting CVE-2026-75106 and how can users protect themselves?
Attackers can read or overwrite respondents' full submission data through this vulnerability. Affected users should update the platform or temporarily disable the editable-submission feature to protect themselves.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.