CVE-2026-57917 MEDIUM

CVE-2026-57917: Improper Restriction of XML External Entity Reference in proCertum SmartSign

Vendor Asseco
Product proCertum SmartSign
Weakness CWE-611 · XXE
Published July 27, 2026
Last update July 27, 2026

CVSS base score

4.8/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N

What the vulnerability does

01Description

proCertum SmartSign parses external XML entities from arbitrary crafted signature files, enabling SSRF and potentially allowing the reading of local files, depending on the parser's configuration. The XML External Entity (XXE) vulnerability is triggered simply by previewing a file in the file selection window, before the victim clicks “Open”. This issue was fixed in version 9.4.3.90.

Key dates

02Disclosure timeline

July 27, 2026 CVE published
July 27, 2026 Record updated

Related vulnerabilities

04Related CVE