CVE-2026-57916 Details
Description
proCertum SmartSign opens Certificate Practice Statement (CPS) URI without schema validation. An attacker can prepare arbitrary certificate with CPS URI pointing to a local executable file or any URL, sign a document with it, and send it to the victim. When the victim opens the document in the application, the specified file will be executed (or webpage will be opened). This issue was fixed in version 9.4.3.90.
A vulnerability exists in proCertum SmartSign versions prior to 9.4.3.90, where the application opens Certificate Practice Statement (CPS) URIs without proper schema validation. This flaw allows an attacker to create a certificate with a CPS URI pointing to a local executable file or any URL. When a document signed with such a certificate is opened by the victim in the application, the specified file is executed or the webpage is opened. Additionally, proCertum SmartSign processes external XML entities from signature files, potentially leading to server-side request forgery (SSRF) attacks or local file read vulnerabilities, depending on the XML parser configuration.
Users can update to proCertum SmartSign version 9.4.3.90 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 27, 2026CISA-ADP
Assessed Jul 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert.pl/posts/2026/07/CVE-2026-57916 | [email protected] | AdvisoryBundleRemedy |
| https://pomoc.certum.pl/pl/oprogramowanie/procertum-smartsign/ | [email protected] | ProductVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-73 | External Control of File Name or Path | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Asseco proCertum SmartSign | < 9.4.3.90 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 27, 2026 | CVE Modified | CISA-ADP |
| Jul 27, 2026 | New CVE Received | [email protected] |
Volerion