📦 Signserver

by Keyfactor

🔍 What is Signserver?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-26787

MEDIUM CVSS 4.7 Dec 22, 2025

A logic error in Keyfactor SignServer container startup resets certificate access controls to 'allowany' on every restart instead of only initial setup. This allows any user with a valid trusted clien...

CVE-2025-47220

MEDIUM CVSS 5.3 Nov 13, 2025

This vulnerability allows admin users in Keyfactor SignServer to enumerate local files by setting the VISIBLE_SIGNATURE_CUSTOM_IMAGE_PATH property to arbitrary paths. When the path points to an existi...

CVE-2025-47221

MEDIUM CVSS 5.3 Nov 13, 2025

This vulnerability allows administrators in Keyfactor SignServer to write arbitrary files to any directory accessible by the JBoss user. Attackers with admin credentials can overwrite existing files, ...