CVE-2026-57917 Details
Description
proCertum SmartSign parses external XML entities from arbitrary crafted signature files, enabling SSRF and potentially allowing the reading of local files, depending on the parser's configuration. The XML External Entity (XXE) vulnerability is triggered simply by previewing a file in the file selection window, before the victim clicks “Open”. This issue was fixed in version 9.4.3.90.
An XML External Entity (XXE) vulnerability has been identified in proCertum SmartSign versions prior to 9.4.3.90. This vulnerability allows the application to parse external XML entities from maliciously crafted signature files, potentially leading to Server-Side Request Forgery (SSRF) attacks and the unauthorized reading of local files, depending on the configuration of the XML parser. The XXE vulnerability is triggered when a file is previewed in the file selection window, before the user clicks 'Open'.
Users can upgrade to proCertum SmartSign version 9.4.3.90 or later to address this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 27, 2026CISA-ADP
Assessed Jul 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert.pl/posts/2026/07/CVE-2026-57916 | [email protected] | AdvisoryBundleRemedy |
| https://pomoc.certum.pl/pl/oprogramowanie/procertum-smartsign/ | [email protected] | ProductVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-611 | Improper Restriction of XML External Entity Reference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Asseco proCertum SmartSign | < 9.4.3.90 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 27, 2026 | CVE Modified | CISA-ADP |
| Jul 27, 2026 | New CVE Received | [email protected] |
Volerion