top of page
perceptive_background_267k.jpg

An unauthenticated information disclosure vulnerability exists in Newgen OmniDocs due to missing authentication and access control on the /omnidocs/GetListofCab…

Published:

22 January 2026 at 23:00:00

Alert date:

23 January 2026 at 23:01:34

Source:

nvd.nist.gov

Click to open the original link from this advisory

Enterprise Applications, Web Technologies

An unauthenticated information disclosure vulnerability in Newgen OmniDocs allows remote attackers to access the /omnidocs/GetListofCabinet API endpoint without credentials. The vulnerability enables unauthorized retrieval of sensitive internal configuration information including cabinet names and database metadata. This missing authentication and access control issue allows enumeration of backend deployment details. The vulnerability may facilitate further targeted attacks against affected systems. Organizations using Newgen OmniDocs should implement proper authentication controls on the affected API endpoint.

Technical details

Mitigation steps:

Affected products:

Newgen OmniDocs

Related links:

Related CVE's:

Related threat actors:

IOC's:

/omnidocs/GetListofCabinet

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page