CVE-2026-57917
Improper Restriction of XML External Entity Reference in proCertum SmartSign
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
proCertum SmartSign parses external XML entities from arbitrary crafted signature files, enabling SSRF and potentially allowing the reading of local files, depending on the parser's configuration. The XML External Entity (XXE) vulnerability is triggered simply by previewing a file in the file selection window, before the victim clicks “Open”. This issue was fixed in version 9.4.3.90.
| CWE | CWE-611 |
| Vendor | asseco |
| Product | procertum smartsign |
| Published | Jul 27, 2026 |
Stay Ahead of the Next One
Get instant alerts for asseco procertum smartsign
Be the first to know when new unknown vulnerabilities affecting asseco procertum smartsign are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
Asseco / proCertum SmartSign
0 < 9.4.3.90
References
Credits
Mariusz Maik