CVE-2026-72689

7.5

OpenSignLabs · opensignserver

A broken object-level authorization vulnerability exists in OpenSignLabs opensignserver, allowing unauthorized access to restricted resources.

Executive summary

An unauthenticated attacker can bypass authorization controls in OpenSignLabs opensignserver, potentially leading to unauthorized data exposure.

Vulnerability

This is a broken object-level authorization vulnerability (CWE-639) that allows unauthenticated users to access sensitive resources by manipulating object identifiers.

Business impact

The vulnerability carries a CVSS score of 7.5, indicating a high severity risk. Successful exploitation could result in significant data breaches or unauthorized disclosure of sensitive information handled by the server, potentially leading to regulatory non-compliance and reputational damage.

Remediation

Immediate Action: Administrators should monitor the vendor repository for the release of version 2.37.1 or later and apply the update immediately upon availability.

Proactive Monitoring: Review web server access logs for anomalous patterns where users attempt to access object IDs outside of their expected scope.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block suspicious requests that target object-level identifiers in API calls.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the high CVSS score and the potential for unauthorized data access, this vulnerability should be treated as a priority. Security teams must remain vigilant for patch releases and ensure that monitoring tools are configured to detect unauthorized access attempts against sensitive API endpoints.

More OpenSignLabs CVEs