Newsy / CERT
Vulnerability in OptimiDoc Server (On-Premise) software
CVE ID: CVE-2026-15933
Publication date: 03 September 2026
Vendor: OptimiDoc
Product: OptimiDoc Server
Vulnerable versions: All before 26.08
Vulnerability type (CWE): Plaintext Storage of a Password (CWE-256)
Report source: Report to CERT Polska
Description
CERT Polska has received a report about vulnerability in OptimiDoc Server (On-Premise) software and participated in coordination of its disclosure.
The vulnerability CVE-2026-15933: OptimiDoc Server (On-Premise) stores credentials for external services in cleartext. An authenticated administrator can view previously configured service passwords, including SMTP, FTP (for scan delivery), Active Directory (for user list import), and SharePoint credentials, in cleartext via the web administration panel page source, allowing exposure of sensitive third-party authentication data.
This issue was fixed in version 26.08
Credits
We thank Paweł Różański from securitum.com for the responsible vulnerability report.
More about the coordinated vulnerability disclosure process at CERT Polska can be found at https://cert.pl/en/cvd/.