CVE-2026-57917

MEDIUM

Improper Restriction of XML External Entity Reference in proCertum SmartSign

Title source: cna
STIX 2.1

Description

proCertum SmartSign parses external XML entities from arbitrary crafted signature files, enabling SSRF and potentially allowing the reading of local files, depending on the parser's configuration. The XML External Entity (XXE) vulnerability is triggered simply by previewing a file in the file selection window, before the victim clicks “Open”. This issue was fixed in version 9.4.3.90.

References (2)

Core 2
Core References
Third Party Advisory third-party-advisory
https://cert.pl/posts/2026/07/CVE-2026-57916

Scores

CVSS v4 4.8
EPSS 0.0014
EPSS Percentile 3.4%
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-611
Status published
Products (1)
Asseco/proCertum SmartSign < 9.4.3.90
Published Jul 27, 2026
Tracked Since Jul 27, 2026