CRITICALVulnerability
Verified
Global

NVD CRITICAL: CVE-2026-75106 — OpnForm derives editable-submission secrets from sequential row identifiers usin...

·Source: NIST NVD

Updated:

Executive Summary

OpnForm derives editable-submission secrets from sequential row identifiers using Hashids with an empty default salt, allowing unauthenticated attackers to compute hashes for any submission. Attackers can read other respondents' full submission data through the submission-fetch endpoint or overwrite submissions by supplying predicted hashes to the answer endpoint.

Analysis

OpnForm derives editable-submission secrets from sequential row identifiers using Hashids with an empty default salt, allowing unauthenticated attackers to compute hashes for any submission. Attackers can read other respondents' full submission data through the submission-fetch endpoint or overwrite submissions by supplying predicted hashes to the answer endpoint. CVSS Score: 9.1. Published: 2026-08-17T21:16:49.610.

Indicators of Compromise (1)

CVE (1)
CVE-2026-75106
Source Attribution

Originally published by NIST NVD on Aug 17, 2026. Verified by: NIST.

Related Threats