CVE-2026-57916

Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
27/07/2026
Last modified:
27/07/2026

Description

proCertum SmartSign opens Certificate Practice Statement (CPS) URI without schema validation. An attacker can prepare arbitrary certificate with CPS URI pointing to a local executable file or any URL, sign a document with it, and send it to the victim. When the victim opens the document in the application, the specified file will be executed (or webpage will be opened).<br /> <br /> This issue was fixed in version 9.4.3.90.