ctipilot.ch
← Back to Daily brief 2026-06-02
NOTABLECVE-2026-8931vulnerability

CVE-2026-8931 — Disig Web Signer: critical RCE in a Slovak electronic-signature client

discovered 2026-06-02 05:00 UTCrun 2026-06-02-8af85d012 sourcesmulti-source

ENISA's EU Vulnerability Database, on an entry assigned by SK-CERT, records CVE-2026-8931 as a critical remote-code-execution vulnerability in Disig Web Signer 2.0.3–2.5.3 with a CVSS 4.0 base score of 9.4 (ENISA EUVD EUVD-2026-33648, 2026-06-01 · Disig vendor advisory). Web Signer is the client-side electronic-signature application published by the Slovak trust-service vendor Disig. The CVSS 4.0 vector (AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H) indicates network exploitability requiring only that a user trigger the signing workflow — e.g. via a malicious document or page — with high impact on subsequent systems (SC:H/SI:H/SA:H), reflecting the client's integration into the applications that invoke it. Disig's advisory directs users to update; the fixed release is Web Signer 2.5.5. No in-the-wild exploitation was reported at disclosure.

PROVENANCE

AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.