Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
| Link | Providers |
|---|---|
| https://github.com/OpenSignLabs/OpenSign |
|
Tue, 11 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Aug 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An insecure direct object reference vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to retrieve any contact record via the getcontact Parse cloud function. The function executes with useMasterKey and performs no authentication or authorization checks before returning the requested contact object. An attacker can enumerate and read all contact records including personally identifiable information without credentials. | |
| Title | OpenSignLabs OpenSign - Insecure Direct Object Reference | |
| Weaknesses | CWE-639 | |
| References |
| |
| Metrics |
cvssV3_1
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: TuranSec
Published:
Updated: 2026-08-11T14:48:32.244Z
Reserved: 2026-08-10T10:32:49.080Z
Link: CVE-2026-72543
Updated: 2026-08-11T14:48:11.878Z
Status : Received
Published: 2026-08-11T12:17:39.727
Modified: 2026-08-11T15:17:35.407
Link: CVE-2026-72543
No data.
OpenCVE Enrichment
Updated: 2026-08-11T18:00:25Z