| CVE ID | CVE-2026-57916 |
| Publication date | 27 July 2026 |
| Vendor | Asseco |
| Product | proCertum SmartSign |
| Vulnerable versions | All before 9.4.3.90 |
| Vulnerability type (CWE) | External Control of File Name or Path (CWE-73) |
| Report source | Report to CERT Polska |
| CVE ID | CVE-2026-57917 |
| Publication date | 27 July 2026 |
| Vendor | Asseco |
| Product | proCertum SmartSign |
| Vulnerable versions | All before 9.4.3.90 |
| Vulnerability type (CWE) | Improper Restriction of XML External Entity Reference (CWE-611) |
| Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerabilities in proCertum SmartSign software and participated in coordination of their disclosure.
The vulnerability CVE-2026-57916: proCertum SmartSign opens Certificate Practice Statement (CPS) URI without schema validation. An attacker can prepare arbitrary certificate with CPS URI pointing to a local executable file or any URL, sign a document with it, and send it to the victim. When the victim opens the document in the application, the specified file will be executed (or webpage will be opened).
The vulnerability CVE-2026-57917: proCertum SmartSign parses external XML entities from arbitrary crafted signature files, enabling SSRF and potentially allowing the reading of local files, depending on the parser's configuration. The XML External Entity (XXE) vulnerability is triggered simply by previewing a file in the file selection window, before the victim clicks “Open”.
These issues were fixed in version 9.4.3.90.
Credits
We thank Mariusz Maik for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.