CVE-2026-72548
An information disclosure vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to retrieve any orga
CVSS
7.5
High
EPSS
—
KEV
—
Exploit Today
—
0-100
Published: Aug 11, 2026 · Last modified: Aug 11, 2026 · CWE-200
Not enough EPSS history yet.
An information disclosure vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to retrieve any organisation tenant record via the gettenant Parse cloud function. The function accepts a contactId parameter and returns the full tenant record without authentication or authorization checks. An attacker can enumerate and disclose tenant configuration data for any organisation in the system.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-73082——
———Activepieces is an open source AI workflow automation platform. Prior to 0.82.0, the POST /api/v1/projects/:projectId/mcp-server/validate-agent-mcp-tool endpoint makes an outbound HTTP or SSE request to a user-supplied serverUrl without URL validation or SSRF protection. An authenticated user can cause the Activepieces server to connect to internal services, cloud metadata endpoints, or arbitrary external hosts and probe network reachability from the Activepieces host. This issue is fixed in version 0.82.0.5hCVE-2026-663016.5 MED—
———Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information over a network.5hCVE-2026-657696.5 MED—
———Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mobile allows an unauthorized attacker to disclose information over a network.5hCVE-2026-619246.5 MED—
———Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.5hCVE-2026-619216.5 MED—
———Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.5hCVE-2026-619186.5 MED—
———Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.5h