CVE-2026-57917
Last modified
CVE-2026-57917 is a medium-severity vulnerability rated 4.8/10 on the CVSS scale. proCertum SmartSign parses external XML entities from arbitrary crafted signature files, enabling SSRF and potentially allowing the reading of local files, depending on the parser's configuration. The XML External Entity (XXE) vulnerability is triggered simply by previewing a file in the file selection window, before the victim clicks “Open”. This issue was fixed in version 9.4.3.90.. EPSS estimates a 0.14% chance of exploitation in the next 30 days.
Description
proCertum SmartSign parses external XML entities from arbitrary crafted signature files, enabling SSRF and potentially allowing the reading of local files, depending on the parser's configuration. The XML External Entity (XXE) vulnerability is triggered simply by previewing a file in the file selection window, before the victim clicks “Open”. This issue was fixed in version 9.4.3.90.
Metrics
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Asseco | proCertum SmartSign | < 9.4.3.90 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-57917?
How severe is CVE-2026-57917?
How do I fix CVE-2026-57917?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-5791Cross-Site request forgery (CSRF) vulnerability in DivvyDriv…6.5
- CVE-2026-57912Johnson & Johnson Campus Recruiting before 2025-10-31 allows…7.5
- CVE-2026-57913Johnson & Johnson Audit Tracking Management System (ATMS) be…7.5
- CVE-2026-57914By sending a deeply nested ASN1 structure to a Apache Kerby …6.5
- CVE-2026-57915It is possible to bypass the Kerberos pre-authentication che…7.3
- CVE-2026-57916proCertum SmartSign opens Certificate Practice Statement (CP…4.6
- CVE-2026-57918libnfs through 6.0.2 before 935b8db has an xid integer under…7.1
- CVE-2026-57919PBackupVSS.exe in Matrix42 Empirum before 25.5 and 26.x befo…7.8
- CVE-2026-5792Authentication bypass by spoofing vulnerability in Hedef Med…6.5
- CVE-2026-57920Peplink InControl 2 through 2.14.2 before 2026-06-03 allows …7.7
- CVE-2026-57921In JetBrains YouTrack before 2026.2.16593 improper access co…7.5
- CVE-2026-57922In JetBrains YouTrack before 2026.2.16593 project settings d…5.3
Are you affected by CVE-2026-57917?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
