| CVE ID | CVE-2026-15933 |
| Publication date | 03 September 2026 |
| Vendor | OptimiDoc |
| Product | OptimiDoc Server |
| Vulnerable versions | All before 26.08 |
| Vulnerability type (CWE) | Plaintext Storage of a Password (CWE-256) |
| Report source | Report to CERT Polska |
Description
CERT Polska has received a report about vulnerability in OptimiDoc Server (On-Premise) software and participated in coordination of its disclosure.
The vulnerability CVE-2026-15933: OptimiDoc Server (On-Premise) stores credentials for external services in cleartext. An authenticated administrator can view previously configured service passwords, including SMTP, FTP (for scan delivery), Active Directory (for user list import), and SharePoint credentials, in cleartext via the web administration panel page source, allowing exposure of sensitive third-party authentication data.
This issue was fixed in version 26.08
Credits
We thank Paweł Różański from securitum.com for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.