🔐 CVE Alert

CVE-2026-15933

UNKNOWN 0.0

Cleartext Storage of Sensitive Credentials in OptimiDoc Server (On-Premise)

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

OptimiDoc Server (On-Premise) stores credentials for external services in cleartext. An authenticated administrator can view previously configured service passwords, including SMTP, FTP (for scan delivery), Active Directory (for user list import), and SharePoint credentials, in cleartext via the web administration panel page source, allowing exposure of sensitive third-party authentication data. This issue was fixed in version 26.08

CWE CWE-256
Vendor optimidoc
Product optimidoc server
Published Sep 3, 2026
Last Updated Sep 3, 2026
Stay Ahead of the Next One

Get instant alerts for optimidoc optimidoc server

Be the first to know when new unknown vulnerabilities affecting optimidoc optimidoc server are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

OptimiDoc / OptimiDoc Server
0 < 26.08

References

NVD ↗ CVE.org ↗ EPSS Data ↗
cert.pl: https://cert.pl/en/posts/2026/09/CVE-2026-15933 optimidoc.com: https://optimidoc.com/category/optimidoc-server/

Credits

Paweł Różański (securitum.com)