Summary
CVE-2026-92794 is a missing-authorization vulnerability in OpenSign, an open-source document signing platform. The flaw resides in the getDocument cloud function, which fails to validate caller identity when one-time-password (OTP) verification is disabled for a document, allowing an unauthenticated attacker to retrieve complete document records — including signer and sender identity and valid download tokens. The vulnerability is rated HIGH severity (CVSS 8.7).
Technical details
- Root cause: the
getDocumentcloud function performs its lookup using a master key and returns the full document object whenever the document’sIsEnableOTPflag is false, without verifying that the caller is authorized to view that document. - Trigger condition: an attacker only needs a valid document identifier (obtainable from a guest signing link) for a document where OTP verification has not been enabled.
- Attack vector: network-based, low complexity, no authentication or user interaction required.
- Impact: disclosure of complete document details, including signer information, sender identity, and valid document download tokens, without any authentication.
Affected software
- OpenSign (OpenSignLabs), versions up to and including 2.41.3.
Severity
- CVSS v3.1 Base Score: 7.5 (HIGH) —
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - CVSS v4.0 Base Score: 8.7 (HIGH) —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Mitigation and recommended actions
- Immediate: upgrade OpenSign to a version beyond 2.41.3 where this issue has been addressed.
- If a patch cannot be applied immediately:
- Enable OTP verification (
IsEnableOTP) on all documents to require an authenticated verification step before document data can be retrieved. - Restrict or monitor access to the
getDocumentcloud function endpoint, and treat guest signing link identifiers as sensitive values. - Review document access/audit logs for unexpected
getDocumentcalls using known or guessable document identifiers.
- Enable OTP verification (

