eParakstītājs must be updated by 3 September: older versions will be disabled

eParakstītājs must be updated by 3 September: older versions will be disabled

Companies using eParakstītājs 3.0 for electronic document signing should ensure that version 1.10.0 or newer is installed by 3 September 2026. LVRTC has announced that older versions will be disabled on that date and will no longer be usable for document signing.

Why is the update required?

A security vulnerability identified as CVE-2026-0392 was fixed in the Windows version of eParakstītājs 3.0 in July. Under specific conditions on an insecure or compromised network, an attacker could have attempted to interfere with the software update process and redirect the user to malicious content instead of an official update.

LVRTC emphasises that the cryptographic security of eSignature was not compromised. The vulnerability did not affect eID cards, PIN codes or the validity of documents that had already been signed.

How can a company check its computers?

  1. Open eParakstītājs 3.0.
  2. Check the installed software version.
  3. If it is 1.10.0 or newer, no further update is required because of this notice.
  4. If an older version is installed, download the latest software only from the official eParaksts website.

Check every workstation, not just one

If eParakstītājs is used by several departments, companies should check every workstation where the application is installed. This is particularly relevant for accounting, legal, administration and management computers.

IT administrators should identify all installations, verify versions centrally where possible, update outdated workstations and test document signing after deployment.

What if the computer is connected to an untrusted network?

LVRTC advises users not to rely on the application's built-in automatic updater when connected to an untrusted data network. The safer option is to download the current installer directly from the official eParaksts website.

Why should companies act before the deadline?

After 3 September, older versions of eParakstītājs 3.0 will be disabled. An employee could otherwise discover that the application no longer works only when an urgent contract, invoice, application or other document needs to be signed.

The safest approach is to verify every eParakstītājs 3.0 installation before the deadline rather than waiting until 3 September.

Frequently asked questions

Which version is required?

Version 1.10.0 or newer must be used.

What happens to older versions after 3 September?

LVRTC states that they will be disabled and will no longer be usable for document signing.

Were PIN codes or previously signed documents compromised?

No. LVRTC states that the vulnerability did not affect eSignature cryptographic security, eID cards, PIN codes or previously signed documents.

Official information sources

Comments

No comments yet. Yours could be the first!

Add a comment