top of page
perceptive_background_267k.jpg

An unauthenticated information disclosure vulnerability exists in Newgen OmniDocs due to missing authentication and access control on the /omnidocs/GetListofCab…

Published:

22 januari 2026 om 23:00:00

Alert date:

23 januari 2026 om 23:01:34

Source:

nvd.nist.gov

Click to open the original link from this advisory

Enterprise Applications, Web Technologies

An unauthenticated information disclosure vulnerability in Newgen OmniDocs allows remote attackers to access the /omnidocs/GetListofCabinet API endpoint without credentials. The vulnerability enables unauthorized retrieval of sensitive internal configuration information including cabinet names and database metadata. This missing authentication and access control issue allows enumeration of backend deployment details. The vulnerability may facilitate further targeted attacks against affected systems. Organizations using Newgen OmniDocs should implement proper authentication controls on the affected API endpoint.

Technical details

Mitigation steps:

Affected products:

Newgen OmniDocs

Related links:

Related CVE's:

Related threat actors:

IOC's:

/omnidocs/GetListofCabinet

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page