CVE-2026-57917
MEDIUMImproper Restriction of XML External Entity Reference in proCertum SmartSign
Title source: cnaDescription
proCertum SmartSign parses external XML entities from arbitrary crafted signature files, enabling SSRF and potentially allowing the reading of local files, depending on the parser's configuration. The XML External Entity (XXE) vulnerability is triggered simply by previewing a file in the file selection window, before the victim clicks “Open”. This issue was fixed in version 9.4.3.90.
References (2)
Core 2
Core References
Third Party Advisory third-party-advisory
https://cert.pl/posts/2026/07/CVE-2026-57916
Product product
https://pomoc.certum.pl/pl/oprogramowanie/procertum-smartsign/
Scores
CVSS v4
4.8
EPSS
0.0014
EPSS Percentile
3.4%
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
no
Technical Impact
partial
Details
CWE
CWE-611
Status
published
Products (1)
Asseco/proCertum SmartSign
< 9.4.3.90
Published
Jul 27, 2026
Tracked Since
Jul 27, 2026