CVE-2026-25825
Arbitrary File Write
Issue summary
The output file that SignerStatusReportWorker logs the report to can be set to any path, even one that will point to a file that already exists. This vulnerability gives a user with admin access the possibility to write files in arbitrary directories in the server file system and potentially overwrite files accessible by the local user JBoss.
Severity
Keyfactor rates the severity as medium with a CVSS score of CVSS 6.9. Assigned CVE-2026-25825.
Who is affected?
All SignServer users prior to 7.6.0.
Risk assessment
An authorized Admin user could mistakenly or by choice overwrite any file on the server accessible by local user JBoss.
Mitigation
Upgrade to SignServer 7.6.0 or later.
Additional information
Should you have any additional questions, please reach out to support@keyfactor.com.
Comments
Article is closed for comments.