SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-57916

MEDIUM · CVSS 4.6 EPSS 0.08%

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

proCertum SmartSign is vulnerable due to its failure to validate the schema of Certificate Practice Statement (CPS) URIs, allowing attackers to craft malicious certificates that can execute arbitrary local files or open URLs when a victim interacts with a signed document. This vulnerability poses a significant risk as it can lead to unauthorized code execution on the victim's system. Organizations using affected versions of proCertum SmartSign should prioritize updating to version 9.4.3.90 to mitigate this risk.

CVE
CVE-2026-57916
Severity
MEDIUM
CVSS
4.6
EPSS
0.08%

Original NVD Description

proCertum SmartSign opens Certificate Practice Statement (CPS) URI without schema validation. An attacker can prepare arbitrary certificate with CPS URI pointing to a local executable file or any URL, sign a document with it, and send it to the victim. When the victim opens the document in the application, the specified file will be executed (or webpage will be opened). This issue was fixed in version 9.4.3.90.