CVE-2026-28803 Details
Description
Open Forms allows users create and publish smart forms. Prior to 3.3.13 and 3.4.5, to be able to cosign, the cosigner receives an e-mail with instructions or a deep-link to start the cosign flow. The submission reference is communicated so that the user can retrieve the submission to be cosigned. Attackers can guess a code or modify the received code to look up arbitrary submissions, after logging in (with DigiD/eHerkenning/... depending on form configuration). This vulnerability is fixed in 3.3.13 and 3.4.5.
A vulnerability in Open Forms prior to versions 3.3.13 and 3.4.5 allows users to access arbitrary submission details by guessing or modifying submission reference codes. This issue arises in the cosigning process, where a cosigner receives an email with a reference code to access a submission. After logging in, attackers can exploit this by guessing codes or altering received ones to retrieve submissions from other users, potentially leading to unauthorized access to sensitive data. The impact varies depending on the form's registration plugin and the sequential nature of case numbers in the downstream system.
Users can update to Open Forms versions 3.3.13, 3.4.5, or the main branch, all of which include the necessary patch. After updating, the submission lookup process has been modified to include a verification step, ensuring that only the intended cosigner can access the submission. Additionally, the API now has rate limits to prevent brute-force attempts.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Mar 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/open-formulieren/open-forms/security/advisories/GHSA-2g49-rfm6-5qj5 | [email protected] | MitigationVendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-noinfo | Insufficient Information to Classify Weakness | [email protected] |
| CWE-284 | Improper Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| maykinmedia open forms | < 3.3.13 >= 3.4.0, < 3.4.5 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 17, 2026 | Initial Analysis | [email protected] |
| Mar 11, 2026 | New CVE Received | [email protected] |