Weaknesses in the authorization mechanisms of Viafirma Documents v3.7.129 allow an authenticated user without privileges to list and access other user data, use user creation, modification, and deletion features, and escalate privileges by impersonating other users of the application in the generation and signing of documents.
References
| Link | Resource |
|---|---|
| https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-viafirma-products | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
29 Jan 2026, 20:12
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:viafirma:documents:*:*:*:*:*:-:*:* |
27 Jan 2026, 20:49
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.1 |
| First Time |
Viafirma documents Compose
Viafirma Viafirma documents |
|
| References | () https://www.incibe.es/en/incibe-cert/notices/aviso/multiple-vulnerabilities-viafirma-products - Third Party Advisory | |
| CPE | cpe:2.3:a:viafirma:documents:*:*:*:*:*:*:*:* cpe:2.3:a:viafirma:documents_compose:*:*:*:*:*:*:*:* |
12 Jan 2026, 15:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-01-12 15:16
Updated : 2026-01-29 20:12
NVD link : CVE-2025-41078
Mitre link : CVE-2025-41078
CVE.ORG link : CVE-2025-41078
JSON object : View
Products Affected
viafirma
- documents_compose
- documents
CWE
CWE-863
Incorrect Authorization
