← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 29, 2026 · 17:17via CVEFeed

CVE-2026-82472 - Documenso before 2.13.0 Unauthenticated File Upload via /api/files/upload-pdf

Brief

CVE ID : CVE-2026-82472

Published : Aug. 29, 2026, 5:17 p. m.

  • 3 hours, 57 minutes ago

Description : Documenso before 2.

  • 0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without requiring authentication, session tokens, or API credentials. Unauthenticated attackers can upload arbitrary PDF files indefinitely to exhaust storage resources or fill the database with unlinked document records.

Severity: 7.5

  • HIGH

Visit the link for more details, such as CVSS details, affected products, timeline, and more...

Read more on CVEFeed