CVE-2026-59112
4.4
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P
Summary
Improper verification of cryptographic signature and Improper Check for Unusual or Exceptional Conditions vulnerability in Estonian Information System Authority (RIA) libdigidocpp, DigiDoc4, DigiDoc on Android, and DigiDoc on iOS. This issue affects libdigidocpp: from 4.1.0 before 4.2.1; DigiDoc4: from 4.7.0 before 4.8.2; DigiDoc on Android: from 2.7.0 before 2.7.2; DigiDoc on iOS: from 2.8.0 before 2.8.1.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Estonian Information System Authority (RIA) | libdigidocpp | 4.1.0 < 4.2.1 | affected |
| Estonian Information System Authority (RIA) | DigiDoc4 | 4.7.0 < 4.8.2 | affected |
| Estonian Information System Authority (RIA) | DigiDoc | 2.7.0 < 2.7.2 | affected |
| Estonian Information System Authority (RIA) | DigiDoc | 2.8.0 < 2.8.1 | affected |
Weaknesses
- CWE-347: CWE-347 Improper verification of cryptographic signature
- CWE-754: CWE-754: Improper Check for Unusual or Exceptional Conditions
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: poc
- Automatable: no
- Technical Impact: partial
Additional References
References
- https://github.com/open-eid/libdigidocpp/pull/690
- https://www.id.ee/en/article/ria-soovitab-kasutajatel-uuendada-id-tarkvara-eng/
- https://www.ria.ee/blogi/digidoc-rakendustes-esinenud-turvanorkus-mis-juhtus-ja-kuidas-see-parandati
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.