VYPR
High severity7.1NVD Advisory· Published Apr 1, 2026· Updated Apr 27, 2026

CVE-2026-4947

CVE-2026-4947

Description

Addressed a potential insecure direct object reference (IDOR) vulnerability in the signing invitation acceptance process. Under certain conditions, this issue could have allowed an attacker to access or modify unauthorized resources by manipulating user-supplied object identifiers, potentially leading to forged signatures and compromising the integrity and authenticity of documents undergoing the signing process. The issue was caused by insufficient authorization validation on referenced resources during request processing.

Affected products

1
  • cpe:2.3:a:foxit:esign:*:*:*:*:*:*:*:*
    Range: <2026-03-26

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.