Description
SirenGPS Android Application 2.19.44 is vulnerable to Incorrect Access Control. An authenticated attacker can manipulate user identifier parameters to bypass authorization controls and gain unauthorized READ and WRITE access to other users' personal information. The API fails to validate that the requesting user is authorized to access the target user's data.
Published: 2026-08-05
Score: 8.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The SirenGPS Android Application version 2.19.44 is vulnerable to an Incorrect Access Control flaw. An authenticated attacker can manipulate user identifier parameters in API requests to bypass authorization checks, gaining unintended read and write privileges on other users' personal data. This weakness allows the attacker to compromise data confidentiality and integrity, potentially leading to privacy violations and unauthorized data modification.

Affected Systems

The vulnerability affects the SirenGPS Android Application, specifically version 2.19.44. Users running this version on Android devices are exposed to the risk. No other versions or products are currently listed as impacted.

Risk and Exploitability

The CVSS score of 8.1 indicates high severity because an attacker can directly access and alter personal information of other users. The EPSS score of < 1% indicates a very low but nonzero exploitation probability, yet the flaw can still be exploited by any authenticated account simply by manipulating user ID parameters, so the likelihood of exploitation remains significant. The flaw is not yet listed in the CISA KEV catalog, yet it may already be actively exploited by malicious actors using the mobile app’s API.

Generated by OpenCVE AI on August 6, 2026 at 17:06 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to a version of SirenGPS Android Application that contains the fix for the access control issue
  • Implement server‑side validation to ensure that the user ID in API requests matches the authenticated session and reject mismatches
  • Configure application to log and alert on repeated API calls with altered user identifiers for timely detection
  • If a patch is unavailable, consider disabling or uninstalling the vulnerable application from user devices until remediation is applied

Generated by OpenCVE AI on August 6, 2026 at 17:06 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Title Incorrect Access Control Allows Bypassing Authentication in SirenGPS Android App

Thu, 06 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
Title Incorrect Access Control Allows Bypassing Authentication in SirenGPS Android App
Weaknesses CWE-284

Wed, 05 Aug 2026 22:15:00 +0000

Type Values Removed Values Added
Description SirenGPS Android Application 2.19.44 is vulnerable to Incorrect Access Control. An authenticated attacker can manipulate user identifier parameters to bypass authorization controls and gain unauthorized READ and WRITE access to other users' personal information. The API fails to validate that the requesting user is authorized to access the target user's data.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-06T14:04:30.320Z

Reserved: 2025-10-27T00:00:00.000Z

Link: CVE-2025-63822

cve-icon Vulnrichment

Updated: 2026-08-06T14:04:26.884Z

cve-icon NVD

Status : Received

Published: 2026-08-05T22:17:06.927

Modified: 2026-08-06T15:16:42.020

Link: CVE-2025-63822

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T17:15:01Z

Weaknesses