PT-2026-64889 · Procertum · Smartsign

·

CVE-2026-57917

·

Published

2026-07-27

·

Updated

2026-07-27

CVSS v4.0

4.8

Medium

VectorAV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N
Name of the Vulnerable Software and Affected Versions proCertum SmartSign versions prior to 9.4.3.90
Description proCertum SmartSign parses external XML entities from crafted signature files, which enables Server-Side Request Forgery (SSRF) and potentially allows the reading of local files, depending on the parser's configuration. This XML External Entity (XXE) issue is triggered when a user previews a file in the file selection window, occurring before the file is actually opened.
Recommendations Update to version 9.4.3.90.

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-57917

Affected Products

Smartsign