Cyber News / Article / Vulnerability in OptimiDoc Server (On-Premise) software

Vulnerability in OptimiDoc Server (On-Premise) software
CERT Polska has received a report about vulnerability in OptimiDoc Server (On-Premise) software and participated in coordination of its disclosure.
The vulnerabilityCVE-2026-15933: OptimiDoc Server (On-Premise) stores credentials for external services in cleartext. An authenticated administrator can view previously configured service passwords, including SMTP, FTP (for scan delivery), Active Directory (for user list import), and SharePoint credentials, in cleartext via the web administration panel page source, allowing exposure of sensitive third-party authentication data.
This issue was fixed in version 26.08
We thank PaweÅ RóżaÅski from securitum.com for the responsible vulnerability report.
Related articles
Thomson Reuters Court Software Breach May Have Exposed SSNs and Sealed Data
8 days ago
Fake Software Installers Disable Windows Update and Weaken Microsoft Defender
9 days ago
Critical cPanel Flaw Could Let One Hosting Customer Take Root Control of a Whole Server
14 days ago
You might Also like

LLMjacking Attack Uses Leaked AWS IAM Key to Steal Paid AI Model Access

Fewer attacks, more force: Link11’s European Cyber Report finds new DDoS records for the first half of 2026

