


Perceptive Security
SOC/SIEM Consultancy

An unauthenticated information disclosure vulnerability exists in Newgen OmniDocs due to missing authentication and access control on the /omnidocs/GetListofCab…
Published:
22 januari 2026 om 23:00:00
Alert date:
23 januari 2026 om 23:01:34
Source:
nvd.nist.gov
Enterprise Applications, Web Technologies
An unauthenticated information disclosure vulnerability in Newgen OmniDocs allows remote attackers to access the /omnidocs/GetListofCabinet API endpoint without credentials. The vulnerability enables unauthorized retrieval of sensitive internal configuration information including cabinet names and database metadata. This missing authentication and access control issue allows enumeration of backend deployment details. The vulnerability may facilitate further targeted attacks against affected systems. Organizations using Newgen OmniDocs should implement proper authentication controls on the affected API endpoint.
Technical details
Mitigation steps:
Affected products:
Newgen OmniDocs
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2025-69907
https://github.com/CBx216/CVE-Newgen-Software-Advisories/blob/main/CVE-2025-69907.md
https://newgensoft.com/
Related CVE's:
Related threat actors:
IOC's:
/omnidocs/GetListofCabinet
This article was created with the assistance of AI technology by Perceptive.
