CVE-2026-15933 PUBLISHED

Cleartext Storage of Sensitive Credentials in OptimiDoc Server (On-Premise)

Assigner: CERT-PL
Reserved: 16.07.2026 Published: 03.09.2026 Updated: 03.09.2026

OptimiDoc Server (On-Premise) stores credentials for external services in cleartext. An authenticated administrator can view previously configured service passwords, including SMTP, FTP (for scan delivery), Active Directory (for user list import), and SharePoint credentials, in cleartext via the web administration panel page source, allowing exposure of sensitive third-party authentication data.

This issue was fixed in version 26.08

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor OptimiDoc
Product OptimiDoc Server
Versions Default: unaffected
  • affected from 0 to 26.08 (excl.)

Credits

  • Paweł Różański (securitum.com) finder

References

Problem Types

  • CWE-256 Plaintext Storage of a Password CWE