CVE-2026-15933
Cleartext Storage of Sensitive Credentials in OptimiDoc Server (On-Premise)
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
OptimiDoc Server (On-Premise) stores credentials for external services in cleartext. An authenticated administrator can view previously configured service passwords, including SMTP, FTP (for scan delivery), Active Directory (for user list import), and SharePoint credentials, in cleartext via the web administration panel page source, allowing exposure of sensitive third-party authentication data. This issue was fixed in version 26.08
| CWE | CWE-256 |
| Vendor | optimidoc |
| Product | optimidoc server |
| Published | Sep 3, 2026 |
| Last Updated | Sep 3, 2026 |
Stay Ahead of the Next One
Get instant alerts for optimidoc optimidoc server
Be the first to know when new unknown vulnerabilities affecting optimidoc optimidoc server are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
OptimiDoc / OptimiDoc Server
0 < 26.08
References
Credits
Paweł Różański (securitum.com)