CRITICAL 9.3 NVD
CVE-2026-75106
OpnForm derives editable-submission secrets from sequential row identifiers using Hashids with an empty default salt, allowing unauthenticated attackers to comp
OpnForm derives editable-submission secrets from sequential row identifiers using Hashids with an empty default salt, allowing unauthenticated attackers to compute hashes for any submission. Attackers can read other respondents' full submission data through the submission-fetch endpoint or overwrite submissions by supplying predicted hashes to the answer endpoint.
References
- https://github.com/OpnForm/OpnForm
- https://github.com/OpnForm/OpnForm/commit/6c67ff0a9bc0ac27ae26b32b8e108a176f8161b1
- https://github.com/OpnForm/OpnForm/issues/1259
- https://github.com/OpnForm/OpnForm/releases/tag/v2.0.2
- https://www.vulncheck.com/advisories/opnform-editable-submission-secret-derivation-via-emp
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-08-17 via NVD.
Risk Timeline
CVE Disclosed2026-08-17 · 0 days ago
Remediation Resources
vulnfeed aggregates 11052 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.