CRITICAL
9.1 CVE-2026-75106 Published 17 Aug 2026
OpnForm Predictable Submission Secret Vulnerability
Worried this affects one of your servers?
OpnForm has a predictable submission-secret vulnerability because it derives editable-submission secrets from sequential row identifiers using Hashids with an empty default salt.
Unauthenticated attackers can compute hashes for any submission, allowing them to:
- Read other respondents' full submission data through the submission-fetch endpoint
- Overwrite submissions by supplying predicted hashes to the answer endpoint
Reference: CVE-2026-75106 on NVD
← Back to Security News