CVE-2026-82472
Documenso before 2.13.0 Unauthenticated File Upload via /api/files/upload-pdf
CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th
Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without requiring authentication, session tokens, or API credentials. Unauthenticated attackers can upload arbitrary PDF files indefinitely to exhaust storage resources or fill the database with unlinked document records.
| CWE | CWE-306 |
| Vendor | documenso |
| Product | documenso |
| Published | Aug 29, 2026 |
Stay Ahead of the Next One
Get instant alerts for documenso documenso
Be the first to know when new high vulnerabilities affecting documenso documenso are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
None
Availability
High
Affected Versions
documenso / documenso
0 < 2.13.0
References
github.com: https://github.com/documenso/documenso/commit/4f346d3c2d5264f221e4d787e162f16051e44114 github.com: https://github.com/documenso/documenso/blob/v2.12.0/apps/remix/server/api/files/files.ts github.com: https://github.com/documenso/documenso vulncheck.com: https://www.vulncheck.com/advisories/documenso-before-2.13.0-unauthenticated-file-upload-via-api-files-upload-pdf
Credits
George Chen