CVE-2026-57917 PUBLISHED

Improper Restriction of XML External Entity Reference in proCertum SmartSign

Assigner: CERT-PL
Reserved: 26.06.2026 Published: 27.07.2026 Updated: 27.07.2026

proCertum SmartSign parses external XML entities from arbitrary crafted signature files, enabling SSRF and potentially allowing the reading of local files, depending on the parser's configuration. The XML External Entity (XXE) vulnerability is triggered simply by previewing a file in the file selection window, before the victim clicks “Open”.

This issue was fixed in version 9.4.3.90.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:L/VA:N/SC:L/SI:L/SA:N
CVSS Score: 4.8

Product Status

Vendor Asseco
Product proCertum SmartSign
Versions Default: unaffected
  • affected from 0 to 9.4.3.90 (excl.)

Credits

  • Mariusz Maik finder

References

Problem Types

  • CWE-611 Improper Restriction of XML External Entity Reference CWE

Impacts

  • CAPEC-664 Server Side Request Forgery