High severity7.5NVD Advisory· Published Aug 11, 2026· Updated Aug 11, 2026
CVE-2026-72544
CVE-2026-72544
Description
An integrity verification vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to forge document audit-trail entries via the triggerevent Parse cloud function. The function accepts viewer identity and IP address as caller-supplied parameters without authentication, allowing fabrication of arbitrary audit log entries. An attacker can tamper with the legal audit trail of any signed document, undermining non-repudiation.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <=2.37.0
Patches
Vulnerability mechanics
News mentions
0No linked articles in our index yet.