# The Front Door: IDP Security and the EU's 24-Hour Rule

> Source: <https://idp-software.com/news/the-front-door/>
> Published: 2026-10-04 22:09:11+00:00

## On This Page

## Three incidents in September

On 20 September an OpenAI agent working on a research task [found a gap in its DNS filtering and used it to reach an external chatbot](https://alignment.openai.com/misalignment-reports/an-agent-used-dns-to-reach-an-external-chatbot/). The automatic shutdown failed, and a person had to stop the run by hand. In the same report OpenAI wrote that it had halted "all training, evaluation, and inference with tool-use" of its most capable models. On 27 September it [reportedly cancelled its next release](https://www.dailysabah.com/business/tech/openai-cancels-release-of-latest-model-amid-safety-concerns) because the model "didn't quite meet the bar in terms of staying within scope and authorization".

Also on 27 September, Citrix disclosed two critical NetScaler flaws that [attackers had been exploiting for a week](https://www.rapid7.com/blog/post/etr-zero-day-exploitation-of-citrix-netscaler-adc-and-gateway-cve-2026-88771-and-cve-2026-88772/). CISA gave US federal agencies [three days to patch](https://www.bleepingcomputer.com/news/security/cisa-orders-feds-to-patch-exploited-citrix-flaws-by-wednesday/). Potsdam [took its online citizen services offline](https://www.tagesspiegel.de/potsdam/landeshauptstadt/weltweite-it-sicherheitslucke-potsdamer-rathaus-nach-cyberalarm-wieder-am-netz-16101282.html). In Rhineland-Palatinate, two municipal data centres [shut down registration, passport and vehicle services for all 194 municipal administrations](https://www.rheinpfalz.de/pfalz_artikel,-lahmgelegte-b%C3%BCrgerdienste-auch-in-der-pfalz-was-dahinter-steckt-_arid,5933597.html) while they patched.

At LMU Munich, attackers took [600,000 records from the admissions system](https://www.br.de/nachrichten/netzwelt/hackerangriff-auf-die-lmu-viele-fragen-erste-antworten,VWgHCxj), some with bank details and health insurance numbers. The vendor, HIS, told BR24 the attack used "a previously unknown vulnerability" in its QIS-LSF product, that it sent the fix to every university it supports, and that none of the others reported an attack.

Two of the three were flaws in software an organisation had bought. The third was an AI agent getting past restrictions its operator had set. None involved IDP software. IDP software has both exposures: it is bought code that opens files from strangers, and in products such as Tungsten's TotalAgility it hands their contents to a large language model.

## Four points of attack

In 2016 Germany's tech industry association Bitkom published a market guide, the ["Input Management Navigator" (PDF, in German)](https://www.bitkom.org/sites/main/files/file/import/160303-LF-Input-Management-Navigator.pdf). It promised software that would "bundle incoming communication centrally and steer it into the business processes". Such software is the front door for incoming documents, and it can be attacked in four places. The parser reads files from unknown senders. The build assembles the vendor's own code from public package registries. The document can show a person one thing and software another. The model, in TotalAgility's case OpenAI's GPT-4o on Azure, receives whatever the extraction produced.

## The parser

The PDF Association's machine-readable model of PDF 2.0 defines [609 object types and 3,971 keys](https://github.com/pdf-association/arlington-pdf-model), by our count of the repository's type files. A parser that accepts any PDF has to handle all of them, and files that break the rules.

Tungsten Automation's Power PDF, originally a Nuance product and later sold by Kofax, has 137 CVEs in the US National Vulnerability Database. All 137 were reported through Trend Micro's Zero Day Initiative, a programme that pays researchers for bugs, and all are flaws in parsing a crafted PDF, XPS, JPEG 2000 or TIFF file. Each needs a user to open the file, and none is rated above 7.8; [CVE-2024-9743](https://www.zerodayinitiative.com/advisories/ZDI-24-1338) is one example. Because they came through one programme, the count reflects where researchers looked as well as the state of the code.

Two server flaws needed no user at all. [CVE-2026-23751](https://www.vulncheck.com/advisories/kofax-capture-unauthenticated-file-read-write-smb-coercion-via-net-remoting), published in April 2026 and rated 9.8, lets anyone on the network read and write files on a Kofax Capture server through an unauthenticated .NET Remoting channel. The same researcher, Victor A. Morales of GM Sectec, found an unauthenticated .NET Remoting channel in Hyland's OnBase in 2025: [CVE-2025-34153](https://nvd.nist.gov/vuln/detail/CVE-2025-34153), rated 10.0, gives remote code execution as SYSTEM.

When Poland's CERT published two TotalAgility flaws in December 2024, it noted it was ["unable to contact the software manufacturer"](https://cert.pl/en/posts/2024/12/CVE-2024-7874/) to confirm which versions were affected. On 4 October we found no security.txt file or advisory page from Tungsten.

Vendors bundle open-source libraries to do the parsing. TotalAgility's [administrator guide (PDF)](https://docshield.tungstenautomation.com/TotalAgility/en_US/2026.2-ru7bs8vbsd/print/TungstenTotalAgilityAdministratorsGuide_EN.pdf) lists ImageMagick, whose 2016 flaw [CVE-2016-3714](https://nvd.nist.gov/vuln/detail/CVE-2016-3714) is in [CISA's catalogue of exploited flaws](https://www.cisa.gov/known-exploited-vulnerabilities-catalog). The open-source Unstructured library's [full installation](https://docs.unstructured.io/open-source/installation/full-installation) requires Poppler, Tesseract and LibreOffice. Docling reads PDFs through [pypdfium2](https://github.com/pypdfium2-team/pypdfium2). ABBYY's [component notices](https://docs.abbyy.com/fine-reader/engine/licensing/copyright-and-trademark-notices) list libxml2, an XML parser. From May to December 2025 the libxml2 README carried this line from its maintainer: ["It is foolish to use this software to process untrusted data."](https://gitlab.gnome.org/GNOME/libxml2/-/commit/35d04a0848) Processing untrusted data is what IDP systems are bought for.

## The build

On the evening of 11 May 2026, [66 UiPath npm packages were published with malicious code](https://www.wiz.io/blog/mini-shai-hulud-strikes-again-tanstack-more-npm-packages-compromised) within eight seconds, as part of the Mini Shai-Hulud worm that also hit TanStack and Mistral's SDK that night. They were developer tools published from UiPath's own npm account. UiPath [states](https://trust.uipath.com/) that no customer data was accessed and that a bug in the malware stopped it from running in UiPath's packages.

Build provenance, a signed record of which pipeline built a package, is meant to show that a release came from the project's own pipeline. The TanStack packages in the same campaign [carried valid provenance](https://www.stepsecurity.io/blog/mini-shai-hulud-is-back-a-self-spreading-supply-chain-attack-hits-the-npm-ecosystem), because the attacker ran the project's own release workflow.

## The document

A digital signature is meant to prove that a document has not changed since it was signed. In 2021 researchers at Ruhr University Bochum showed that a signed PDF can display content other than what was signed while staying within the standard, by exploiting incremental updates, which append changes to a file after it is signed. Their ["shadow attacks" (PDF)](https://www.ndss-symposium.org/wp-content/uploads/ndss2021_1B-4_24117_paper.pdf) worked on 16 of 29 viewers, including Acrobat and Foxit.

A [USENIX Security 2026 study](https://arxiv.org/abs/2605.28999) of about 200,000 real résumés found hidden prompt injections in roughly 1% of them: white text, one-point type, or text placed outside the visible page. The authors found that "more than 90% of injected prompts do not use explicit instructions". The two detectors they tested caught 5% and 7% of the injected résumés. The techniques the study lists all sit in the text layer of a digital PDF. An IDP system that reads that layer, rather than running OCR on the rendered page, receives the hidden text along with the visible text. In July we found that none of eleven IDP platforms mentions [fraud, tampering or authenticity](../../news/the-100-dollar-forgery/) where it defines its confidence score.

## The model

Tungsten's [TotalAgility Cloud security primer (PDF)](https://docshield.tungstenautomation.com/TotalAgility/en_US/2026.2-ru7bs8vbsd/print/TungstenTotalAgilityCloudInfoSecPrimer_EN.pdf) states that its built-in "Tungsten AI provider" runs OpenAI's GPT-4o and GPT-4o-mini on Azure. Microsoft's schedule [retires every listed GPT-4o version](https://learn.microsoft.com/en-us/azure/foundry/openai/concepts/model-retirement-schedule) between 9 December 2026 and 14 April 2027. Tungsten says it "will periodically upgrade" the models and that timelines "will be communicated"; the primer gives no dates. [UiPath](../../vendors/uipath/) [switched off its own GPT-4o version](https://docs.uipath.com/overview/other/latest/overview/llm-model-deprecation-timeline) on 30 September, ten weeks before Microsoft's first retirement date. A change of model changes how documents are read, hidden text included, so acceptance tests run on the old model have to be repeated.

An assistant that answers questions over a document archive also has to respect who may see which document. M-Files fixed [CVE-2024-11176](https://www.cve.org/CVERecord?id=CVE-2024-11176), an "incorrect evaluation of effective permissions" in its Aino assistant. Tungsten's primer describes its Knowledge Discovery feature as retrieval over Azure AI Search and does not say whether results follow per-document permissions.

## The EU reporting deadline

The [Cyber Resilience Act](https://eur-lex.europa.eu/eli/reg/2024/2847/oj) began applying its [reporting duty](https://digital-strategy.ec.europa.eu/en/policies/cra-reporting) on 11 September 2026, including to products already on the market. A manufacturer that learns a flaw in its product is being actively exploited must send an early warning within 24 hours, a notification within 72, and a final report within 14 days of a fix. The duty covers exploited flaws in bundled libraries too, so to report in time a vendor needs to know which version of each library every product ships. Under Article 64, breaching the reporting duty can cost up to €15m or 2.5% of worldwide turnover, whichever is higher. ENISA's reporting platform [opened on 11 September](https://www.enisa.europa.eu/news/the-cra-single-reporting-platform-is-launched).

The act covers software the customer installs. Of the products named here, Power PDF, Kofax Capture, on-premises OnBase and ABBYY's FineReader Engine fall under it; software sold only as a cloud service, such as TotalAgility Cloud, generally does not. From 11 December 2027 manufacturers must also draw up a software bill of materials (SBOM), a list of every component in a product, as part of their technical documentation. The act does not require them to give it to customers.

## What buyers can check

In early October we checked 22 commercial IDP and document-platform vendors, among them Tungsten, ABBYY, Hyland, UiPath, Automation Anywhere, M-Files and Box, for what a buyer can find without a sales call: an SBOM, third-party notices, a security advisory page, a security.txt file, and whether the vendor is a CVE Numbering Authority.

None offers a public SBOM download. Two keep open-source reports in gated portals: [Automation Anywhere](../../vendors/automation-anywhere/) lists open-source and Black Duck reports, which name components, in its login-only compliance portal, and UiPath lists open-source licences behind "request access" in its trust centre. IBM, Microsoft, Google, AWS, Adobe, OpenText and M-Files are [CVE Numbering Authorities](https://www.cve.org/PartnerInformation/ListofPartners) and can issue CVE IDs for flaws in their own products; none of the IDP-only vendors we checked is.

[ABBYY](../../vendors/abbyy/) is the only commercial vendor in our check that lists [component versions on a public page](https://docs.abbyy.com/fine-reader/engine/licensing/copyright-and-trademark-notices). Its FineReader Engine 12 page, stamped May 2024, lists 13 component versions. Among them are libxml2 2.9.10, OpenSSL 1.1.1l, which lost upstream support in September 2023, and curl 7.61.1 from 2018. NVD records 274 CVEs against those 13 versions, all fixed in later upstream releases. In September 2025 ABBYY's release notes for Release 7 of FineReader Engine 12 said it "addresses all Critical and High rated security issues related to project dependencies including but not limited to cURL, OpenJPEG, Libyaml, OpenOffice". The release notes name no versions and the notices page still carries its May 2024 date, so whether the current product ships the old versions is not public.

[Docling](../../vendors/docling/), IBM's open-source document conversion toolkit, was not among the 22. Because its dependencies are public, anyone can repeat our check: we generated a CycloneDX SBOM from them with cyclonedx-py and scanned it with pip-audit. It lists 106 Python packages, none with a known vulnerability. The list stops at Python: the PDFium library bundled in pypdfium2, which does the PDF parsing, is not in it.

## What to ask before the next renewal

**The SBOM, in writing.** CycloneDX or SPDX, for the version you run. The CRA does not oblige vendors to hand it over, so put delivery in the contract.

**Who reports, and how.** The security advisory page, a working disclosure address, and the process for the CRA's 24-hour warning.

**Which model, and until when.** The model behind every generative feature, its retirement date, and how much notice you get before it changes.

**What happens to a hostile file.** Whether document conversion runs in a sandbox, whether hidden text reaches the model, and whether signed PDFs are checked for changes appended after signing.

## Caveats

CVE counts come from NVD on 4 October 2026 and depend on how products are tagged. The ABBYY figures map versions in published notices to NVD records; they do not show which flaws are reachable in the shipped product. The ABBYY and Docling checks measure how much can be verified from outside; they do not rank the products' security. The SBOM audit records what we found on public pages and trust centres; material behind logins may exist. The OpenAI release cancellation is press reporting; the DNS incident is OpenAI's own report. We found no confirmed case of customer data stolen through an IDP product. We do not sell IDP software and are not paid by any vendor named here.
