CVE-2026-82472 - Documenso before 2.13.0 Unauthenticated File Upload via /api/files/upload-pdf
Brief
CVE ID : CVE-2026-82472
Published : Aug. 29, 2026, 5:17 p. m.
- 3 hours, 57 minutes ago
Description : Documenso before 2.
- 0 accepts PDF file uploads on the /api/files/upload-pdf endpoint without requiring authentication, session tokens, or API credentials. Unauthenticated attackers can upload arbitrary PDF files indefinitely to exhaust storage resources or fill the database with unlinked document records.
Severity: 7.5
- HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
