{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/documenso/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:documenso:documenso:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-82472"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Documenso (\u003c 2.13.0)"],"_cs_severities":["low"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Documenso"],"content_html":"\u003cp\u003eDocumenso versions prior to 2.13.0 contain an authentication bypass vulnerability, tracked as CVE-2026-82472. The application fails to enforce authentication, session validation, or API credential requirements on the /api/files/upload-pdf endpoint. This allows any unauthenticated actor with network access to the Documenso instance to upload arbitrary PDF files.\u003c/p\u003e\n\u003cp\u003eDefenders should prioritize this vulnerability as it enables unauthorized resource consumption. Attackers can leverage this to exhaust disk storage or populate the application database with excessive unlinked document records, leading to a denial-of-service (DoS) condition. As this endpoint does not validate the source of the upload, it may also be used to bypass intended business workflows.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated remote actors to cause a denial-of-service by overwhelming system resources. This impacts the availability and integrity of the document storage backend and database performance for all users of the affected Documenso instance.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade all instances of Documenso to version 2.13.0 or later to apply the fix for CVE-2026-82472.\u003c/li\u003e\n\u003cli\u003eImplement network-level access controls or a Web Application Firewall (WAF) to restrict access to the /api/files/upload-pdf endpoint to known, trusted IP ranges until patching is complete.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for anomalous, high-frequency POST requests to /api/files/upload-pdf originating from unauthorized or unexpected source IPs.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-29T17:41:10Z","date_published":"2026-08-29T17:41:10Z","id":"https://feed.craftedsignal.io/briefs/2026-08-documenso-auth-bypass/","summary":"Documenso versions prior to 2.13.0 allow unauthenticated attackers to perform arbitrary PDF file uploads via the /api/files/upload-pdf endpoint, potentially resulting in resource exhaustion.","title":"Authentication Bypass in Documenso File Upload Endpoint","url":"https://feed.craftedsignal.io/briefs/2026-08-documenso-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Documenso","version":"https://jsonfeed.org/version/1.1"}