SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-82472

HIGH · CVSS 7.5 EPSS 0.41% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-29 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Documenso versions prior to 2.13.0 are vulnerable due to an unauthenticated endpoint that allows arbitrary PDF file uploads without any authentication or session validation. This can lead to resource exhaustion and database clutter, potentially impacting system performance and availability. Organizations using affected versions should prioritize patching to mitigate the risk of abuse and ensure system integrity.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-82472
Severity
HIGH
CVSS
7.5
EPSS
0.41%

Original NVD Description

Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without requiring authentication, session tokens, or API credentials. Unauthenticated attackers can upload arbitrary PDF files indefinitely to exhaust storage resources or fill the database with unlinked document records.