---
schema: 1
kind: vulnerability
title: "CVE-2026-8931 — Disig Web Signer: critical RCE in a Slovak electronic-signature client"
headline: "CVE-2026-8931 — Disig Web Signer: critical RCE in a Slovak electronic-signature client"
summary: "ENISA's EU Vulnerability Database, on an entry assigned by SK-CERT, records CVE-2026-8931 as a critical remote-code-execution vulnerability in Disig Web Signer 2.0.3–2.5.3 with a CVSS 4.0 base score of 9.4 (ENISA EUVD EUVD-2026-33648, 2026-06-01 · Disig vendor advisory)."
discovered_at: "2026-06-02T05:00:05Z"
event_date: 2026-06-01
run_id: 2026-06-02-8af85d01
priority: notable
immediate_action: null
tags:
  - vulnerabilities
  - rce
  - identity
regions:
  - europe
sectors:
  - public-sector
  - finance
  - legal-services
entities: []
cves:
  - id: CVE-2026-8931
    cvss: "9.4"
    epss: null
    type: rce
    vector: user-interaction
    auth: pre-auth
    status:
      - patch-available
sources:
  - url: "https://euvd.enisa.europa.eu/enisa/eu_vulnerability_database/EUVD-2026-33648"
    publisher: ENISA EUVD EUVD-2026-33648
    role: primary
  - url: "https://www.disig.sk/en/news/important-update-of-the-web-signer-application/"
    publisher: Disig vendor advisory
    role: corroborating
closed_sources: []
evidence: []
verification: multi-source
sourcing_note: null
confidence: high
update_of: null
references: []
deep_dive: false
deep_dive_category: null
org_triage: null
watchlist_hit: false
actions: []
migrated_from: briefs/2026-06-02.md
---

ENISA's EU Vulnerability Database, on an entry assigned by **SK-CERT**, records CVE-2026-8931 as a critical remote-code-execution vulnerability in Disig Web Signer 2.0.3–2.5.3 with a CVSS 4.0 base score of 9.4 ([ENISA EUVD EUVD-2026-33648, 2026-06-01](https://euvd.enisa.europa.eu/enisa/eu_vulnerability_database/EUVD-2026-33648) · [Disig vendor advisory](https://www.disig.sk/en/news/important-update-of-the-web-signer-application/)). Web Signer is the client-side electronic-signature application published by the Slovak trust-service vendor Disig. The CVSS 4.0 vector (`AV:N/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H`) indicates network exploitability requiring only that a user trigger the signing workflow — e.g. via a malicious document or page — with high impact on subsequent systems (`SC:H/SI:H/SA:H`), reflecting the client's integration into the applications that invoke it. Disig's advisory directs users to update; the fixed release is Web Signer 2.5.5. No in-the-wild exploitation was reported at disclosure.
