An information disclosure vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to map any email address or username to its internal user objectId via the getUserId Parse cloud function. The function performs no authentication before resolving and returning the internal identifier. An attacker can use this to enumerate user accounts and target subsequent attacks.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://github.com/OpenSignLabs/OpenSign |
|
History
Thu, 13 Aug 2026 11:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Opensignlabs
Opensignlabs opensignserver |
|
| Vendors & Products |
Opensignlabs
Opensignlabs opensignserver |
Tue, 11 Aug 2026 15:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Aug 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An information disclosure vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to map any email address or username to its internal user objectId via the getUserId Parse cloud function. The function performs no authentication before resolving and returning the internal identifier. An attacker can use this to enumerate user accounts and target subsequent attacks. | |
| Title | OpenSignLabs OpenSign - Information Disclosure | |
| Weaknesses | CWE-200 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: TuranSec
Published: 2026-08-11T11:10:11.231Z
Updated: 2026-08-11T15:09:18.816Z
Reserved: 2026-08-10T10:32:49.081Z
Link: CVE-2026-72549
Updated: 2026-08-11T15:09:14.217Z
Status : Deferred
Published: 2026-08-11T12:17:40.483
Modified: 2026-09-03T17:51:46.420
Link: CVE-2026-72549
No data.