{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/opensign--2.41.3/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:opensign:opensign:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-92794"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["OpenSign (\u003c= 2.41.3)"],"_cs_severities":["high"],"_cs_tags":["authentication-bypass","cloud-security","information-disclosure"],"_cs_type":"advisory","_cs_vendors":["OpenSign"],"content_html":"\u003cp\u003eOpenSign versions through 2.41.3 are susceptible to an authentication bypass vulnerability in the 'getDocument' cloud function. This flaw occurs specifically when one-time-password (OTP) verification is disabled for a document. By exploiting this, an unauthenticated attacker can supply a known document identifier, typically obtained from guest signing links, to the 'getDocument' endpoint. The application fails to validate the caller's identity or authorization status, returning the full document metadata, details for all signers, sender information, and valid download tokens. This exposure poses a significant risk to data confidentiality and integrity, as it allows unauthorized access to documents and potential exfiltration of sensitive information without requiring legitimate user credentials. Organizations utilizing OpenSign must ensure that authentication mechanisms, such as OTP, are enforced and that the product is updated to a patched version once available.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a target document ID, typically by intercepting or observing guest signing links sent to authorized recipients.\u003c/li\u003e\n\u003cli\u003eAttacker verifies that the target document environment is configured with OTP verification disabled, a prerequisite for the bypass.\u003c/li\u003e\n\u003cli\u003eAttacker crafts an HTTP GET or POST request targeting the 'getDocument' cloud function endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker includes the target document identifier in the request parameters.\u003c/li\u003e\n\u003cli\u003eThe OpenSign cloud function processes the request without enforcing session-based authentication or verifying the caller's identity.\u003c/li\u003e\n\u003cli\u003eThe application responds with a JSON payload containing the complete document record, including signer emails, document metadata, and valid file download tokens.\u003c/li\u003e\n\u003cli\u003eAttacker parses the response to extract the download tokens.\u003c/li\u003e\n\u003cli\u003eAttacker uses the extracted download tokens to exfiltrate the full document content from the storage backend.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated actors to harvest sensitive PII and confidential documents managed within OpenSign. This can lead to unauthorized information disclosure, compromise of business contracts, and potential supply chain risk depending on the sensitivity of the signed documents.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eReview current OpenSign document workflows and verify that OTP verification is mandated for all sensitive signing operations.\u003c/li\u003e\n\u003cli\u003eMonitor web server logs for anomalous patterns of requests to the 'getDocument' endpoint, particularly those originating from unauthorized or unexpected IP ranges or those lacking standard authentication headers.\u003c/li\u003e\n\u003cli\u003eMonitor for high volumes of individual document requests that deviate from typical user behavior patterns.\u003c/li\u003e\n\u003cli\u003eUpgrade OpenSign instances to a version beyond 2.41.3 as soon as vendor patches are available.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-16T23:52:06Z","date_published":"2026-09-16T23:52:06Z","id":"https://feed.craftedsignal.io/briefs/2026-09-opensign-auth-bypass/","summary":"OpenSign versions through 2.41.3 contain an authentication bypass vulnerability allowing unauthenticated attackers to retrieve sensitive document data and download tokens when OTP verification is disabled.","title":"Authentication Bypass in OpenSign getDocument Function","url":"https://feed.craftedsignal.io/briefs/2026-09-opensign-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - OpenSign (\u003c= 2.41.3)","version":"https://jsonfeed.org/version/1.1"}