Vulnerability Description
proCertum SmartSign opens Certificate Practice Statement (CPS) URI without schema validation. An attacker can prepare arbitrary certificate with CPS URI pointing to a local executable file or any URL, sign a document with it, and send it to the victim. When the victim opens the document in the application, the specified file will be executed (or webpage will be opened). This issue was fixed in version 9.4.3.90.
Related Weaknesses (CWE)
References
- https://cert.pl/posts/2026/07/CVE-2026-57916
- https://pomoc.certum.pl/pl/oprogramowanie/procertum-smartsign/
FAQ
What is CVE-2026-57916?
CVE-2026-57916 is a documented vulnerability. proCertum SmartSign opens Certificate Practice Statement (CPS) URI without schema validation. An attacker can prepare arbitrary certificate with CPS URI pointing to a local executable file or any URL,...
How severe is CVE-2026-57916?
CVSS scoring is not yet available for CVE-2026-57916. Check NVD for updates.
Is there a patch for CVE-2026-57916?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.