Beveiligingsadvies
CVE-2026-82472
CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations
Beschrijving
Documenso before 2.13.0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without requiring authentication, session tokens, or API credentials. Unauthenticated attackers can upload arbitrary PDF files indefinitely to exhaust storage resources or fill the database with unlinked document records.