CRITICAL 9.3 NVD

CVE-2026-75106

OpnForm derives editable-submission secrets from sequential row identifiers using Hashids with an empty default salt, allowing unauthenticated attackers to comp

OpnForm derives editable-submission secrets from sequential row identifiers using Hashids with an empty default salt, allowing unauthenticated attackers to compute hashes for any submission. Attackers can read other respondents' full submission data through the submission-fetch endpoint or overwrite submissions by supplying predicted hashes to the answer endpoint.

References

Published: 2026-08-17 · Source: NVD · Feed updated: 2026-08-18
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-08-17 via NVD.

Risk Timeline

CVE Disclosed2026-08-17 · 0 days ago

Remediation Resources

vulnfeed aggregates 11052 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.