CVE-2026-72548
An information disclosure vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to retrieve any orga
CVSS
7.5
Alto
EPSS
—
KEV
—
Exploit Today
—
0-100
Publicado: 11 ago 2026 · Última mod.: 11 ago 2026 · CWE-200
Sin historial EPSS suficiente todavía.
An information disclosure vulnerability in OpenSignLabs OpenSign through 2.37.0 allows unauthenticated remote attackers to retrieve any organisation tenant record via the gettenant Parse cloud function. The function accepts a contactId parameter and returns the full tenant record without authentication or authorization checks. An attacker can enumerate and disclose tenant configuration data for any organisation in the system.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-73082——
———Activepieces is an open source AI workflow automation platform. Prior to 0.82.0, the POST /api/v1/projects/:projectId/mcp-server/validate-agent-mcp-tool endpoint makes an outbound HTTP or SSE request to a user-supplied serverUrl without URL validation or SSRF protection. An authenticated user can cause the Activepieces server to connect to internal services, cloud metadata endpoints, or arbitrary external hosts and probe network reachability from the Activepieces host. This issue is fixed in version 0.82.0.6hCVE-2026-663016.5 MED—
———Exposure of sensitive information to an unauthorized actor in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to disclose information over a network.6hCVE-2026-657696.5 MED—
———Exposure of sensitive information to an unauthorized actor in Microsoft Teams Mobile allows an unauthorized attacker to disclose information over a network.6hCVE-2026-619246.5 MED—
———Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.6hCVE-2026-619216.5 MED—
———Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.6hCVE-2026-619186.5 MED—
———Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.6h