CVE-2026-57916

MEDIUM

Arbitrary Path Execution via CPS URI in proCertum SmartSign

Title source: cna
STIX 2.1

Description

proCertum SmartSign opens Certificate Practice Statement (CPS) URI without schema validation. An attacker can prepare arbitrary certificate with CPS URI pointing to a local executable file or any URL, sign a document with it, and send it to the victim. When the victim opens the document in the application, the specified file will be executed (or webpage will be opened). This issue was fixed in version 9.4.3.90.

References (2)

Core 2
Core References
Third Party Advisory third-party-advisory
https://cert.pl/posts/2026/07/CVE-2026-57916

Scores

CVSS v4 4.6
EPSS 0.0008
EPSS Percentile 0.4%
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:L/VA:N/SC:N/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-73
Status published
Products (1)
Asseco/proCertum SmartSign < 9.4.3.90
Published Jul 27, 2026
Tracked Since Jul 27, 2026