{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.2",
    "cveMetadata": {
        "cveId": "CVE-2026-59112",
        "assignerOrgId": "a6d3dc9e-0591-4a13-bce7-0f5b31ff6158",
        "state": "PUBLISHED",
        "assignerShortName": "ENISA",
        "dateReserved": "2026-07-02T15:47:36.965Z",
        "datePublished": "2026-08-10T13:57:37.159Z",
        "dateUpdated": "2026-08-10T17:55:30.587Z"
    },
    "containers": {
        "cna": {
            "providerMetadata": {
                "orgId": "a6d3dc9e-0591-4a13-bce7-0f5b31ff6158",
                "shortName": "ENISA",
                "dateUpdated": "2026-08-10T13:57:37.159Z"
            },
            "title": "Signature validation vulnerability affecting DigiDoc applications",
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "lang": "en",
                            "cweId": "CWE-347",
                            "description": "CWE-347 Improper verification of cryptographic signature",
                            "type": "CWE"
                        }
                    ]
                },
                {
                    "descriptions": [
                        {
                            "lang": "en",
                            "cweId": "CWE-754",
                            "description": "CWE-754: Improper Check for Unusual or Exceptional Conditions",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "affected": [
                {
                    "vendor": "Estonian Information System Authority (RIA)",
                    "product": "libdigidocpp",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "4.1.0",
                            "lessThan": "4.2.1",
                            "versionType": "semver"
                        }
                    ],
                    "defaultStatus": "unaffected"
                },
                {
                    "vendor": "Estonian Information System Authority (RIA)",
                    "product": "DigiDoc4",
                    "versions": [
                        {
                            "status": "affected",
                            "version": "4.7.0",
                            "lessThan": "4.8.2",
                            "versionType": "semver"
                        }
                    ],
                    "defaultStatus": "unaffected"
                },
                {
                    "vendor": "Estonian Information System Authority (RIA)",
                    "product": "DigiDoc",
                    "platforms": [
                        "Android"
                    ],
                    "versions": [
                        {
                            "status": "affected",
                            "version": "2.7.0",
                            "lessThan": "2.7.2",
                            "versionType": "semver"
                        }
                    ],
                    "defaultStatus": "unaffected"
                },
                {
                    "vendor": "Estonian Information System Authority (RIA)",
                    "product": "DigiDoc",
                    "platforms": [
                        "iOS"
                    ],
                    "versions": [
                        {
                            "status": "affected",
                            "version": "2.8.0",
                            "lessThan": "2.8.1",
                            "versionType": "semver"
                        }
                    ],
                    "defaultStatus": "unaffected"
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "value": "Improper verification of cryptographic signature and Improper Check for Unusual or Exceptional Conditions vulnerability in Estonian Information System Authority (RIA) libdigidocpp, DigiDoc4, DigiDoc on Android, and DigiDoc on iOS. This issue affects libdigidocpp: from 4.1.0 before 4.2.1; DigiDoc4: from 4.7.0 before 4.8.2; DigiDoc on Android: from 2.7.0 before 2.7.2; DigiDoc on iOS: from 2.8.0 before 2.8.1.",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "Improper verification of cryptographic signature and Improper Check for Unusual or Exceptional Conditions vulnerability in Estonian Information System Authority (RIA) libdigidocpp, DigiDoc4, DigiDoc on Android, and DigiDoc on iOS.&nbsp;This issue affects libdigidocpp: from 4.1.0 before 4.2.1; DigiDoc4: from 4.7.0 before 4.8.2; DigiDoc on Android: from 2.7.0 before 2.7.2; DigiDoc on iOS: from 2.8.0 before 2.8.1."
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://github.com/open-eid/libdigidocpp/pull/690",
                    "tags": [
                        "patch"
                    ]
                },
                {
                    "url": "https://www.id.ee/en/article/ria-soovitab-kasutajatel-uuendada-id-tarkvara-eng/",
                    "tags": [
                        "vendor-advisory"
                    ]
                },
                {
                    "url": "https://www.ria.ee/blogi/digidoc-rakendustes-esinenud-turvanorkus-mis-juhtus-ja-kuidas-see-parandati",
                    "tags": [
                        "government-resource"
                    ]
                }
            ],
            "metrics": [
                {
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en",
                            "value": "GENERAL"
                        }
                    ],
                    "cvssV4_0": {
                        "attackVector": "LOCAL",
                        "attackComplexity": "LOW",
                        "attackRequirements": "PRESENT",
                        "privilegesRequired": "NONE",
                        "userInteraction": "ACTIVE",
                        "vulnConfidentialityImpact": "NONE",
                        "subConfidentialityImpact": "NONE",
                        "vulnIntegrityImpact": "HIGH",
                        "subIntegrityImpact": "NONE",
                        "vulnAvailabilityImpact": "NONE",
                        "subAvailabilityImpact": "NONE",
                        "exploitMaturity": "PROOF_OF_CONCEPT",
                        "Safety": "NOT_DEFINED",
                        "Automatable": "NOT_DEFINED",
                        "Recovery": "NOT_DEFINED",
                        "valueDensity": "NOT_DEFINED",
                        "vulnerabilityResponseEffort": "NOT_DEFINED",
                        "providerUrgency": "NOT_DEFINED",
                        "version": "4.0",
                        "baseSeverity": "MEDIUM",
                        "baseScore": 4.4,
                        "vectorString": "CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:A/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N/E:P"
                    }
                }
            ],
            "solutions": [
                {
                    "lang": "en",
                    "value": "Systems integrating libdigidocpp should update to\nversion 4.2.1 or later. \nUsers of DigiDoc applications should update to fixed\nversions provided by the vendor: \nDigiDoc4 - 4.8.2 or later, RIA DigiDoc Android\n- 2.7.2 or later, and RIA DigiDoc iOS - 2.8.1 or later. \nSignatures that were validated\nwith the vulnerable software versions should be revalidated.",
                    "supportingMedia": [
                        {
                            "type": "text/html",
                            "base64": false,
                            "value": "<span>Systems integrating libdigidocpp should update to\nversion 4.2.1 or later.&nbsp;<br>Users of DigiDoc applications should update to fixed\nversions provided by the vendor:&nbsp;<br>DigiDoc4 - 4.8.2 or later, RIA DigiDoc Android\n- 2.7.2 or later, and RIA DigiDoc iOS - 2.8.1 or later.&nbsp;<br>Signatures that were validated\nwith the vulnerable software versions should be revalidated.</span>"
                        }
                    ]
                }
            ],
            "credits": [
                {
                    "lang": "en",
                    "value": "Burak Can Kus & Aleksander Kamenik (Cybernetica)",
                    "type": "finder"
                }
            ],
            "source": {
                "discovery": "UNKNOWN"
            },
            "x_generator": {
                "engine": "Vulnogram 1.0.4"
            }
        },
        "adp": [
            {
                "references": [
                    {
                        "url": "https://github.com/open-eid/libdigidocpp/pull/690",
                        "tags": [
                            "exploit"
                        ]
                    }
                ],
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2026-08-10T17:55:03.112154Z",
                                "id": "CVE-2026-59112",
                                "options": [
                                    {
                                        "Exploitation": "poc"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "partial"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2026-08-10T17:55:30.587Z"
                }
            }
        ]
    }
}