ZeroHour

CVE-2026-85697

niche

Incorrect authorization in Documenso PDF endpoint leaks restricted documents

CVSS 4.0
7.1 high
EPSS
<1%p23
Published
()
Modified
AI analysis

Documenso 2.17.0 contains an access control flaw (CWE-863, incorrect authorization) in the endpoint that serves PDF documents: it fails to validate document visibility settings and does not verify that the requester owns or is authorized to view the document being requested. A low-privileged authenticated user who knows or guesses a document's data identifier can request that document's PDF and retrieve it even when visibility settings should restrict it, including documents in other teams or tenants. The attacker gains read access to restricted signed documents, a confidentiality-only impact, with no ability to modify or disrupt anything (CVSS 4.0 confidentiality impact is high while integrity and availability impacts are none). Any organization running Documenso 2.17.0, particularly multi-team or multi-tenant deployments where documents are meant to be team-restricted, is exposed. There is no public proof-of-concept, the issue is not in CISA KEV, and EPSS puts 30-day exploitation probability at just 0.3% (23rd percentile), so no exploitation is currently known.

What to do: Upgrade to the latest Documenso release beyond 2.17.0 as soon as a patched build is available, and monitor the vendor's GitHub security advisories for the fixed version since the advisory data does not name one. In the meantime, restrict and audit access to the PDF-serving endpoint, review team/tenant document sharing and visibility settings, and check access logs for low-privileged accounts fetching documents outside their team or tenant.

Affected
Documenso2.17.0 (specific affected range and fixed version not stated in the available advisory data)
Estimated exposure
nicheroughly thousands of deployments (self-hosted open-source signing platform plus its hosted service; no public install counts) — Documenso is a relatively new open-source e-signature alternative deployed mostly self-hosted with no public telemetry, so based on deployment patterns for emerging open-source signing tools, adoption is plausibly on the order of thousands…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Documenso 2.17.0 contains an access control vulnerability in the PDF-serving endpoint that fails to validate document visibility settings. Attackers with low privileges can read restricted documents within their team or cross-tenant by leveraging missing ownership validation on document data identifiers.

Weakness
CWE-863
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.