Description
Missing Authentication for Critical Function, Improper Access Control vulnerability in Dinosoft Business Solutions Dinosoft ERP allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Dinosoft ERP: from < 3.0.1 through 11022026.

NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-02-11
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 11 Feb 2026 22:15:00 +0000

Type Values Removed Values Added
First Time appeared Dinosoft Business Solutions
Dinosoft Business Solutions dinosoft Erp
Vendors & Products Dinosoft Business Solutions
Dinosoft Business Solutions dinosoft Erp

Wed, 11 Feb 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 11 Feb 2026 12:45:00 +0000

Type Values Removed Values Added
Description Missing Authentication for Critical Function, Improper Access Control vulnerability in Dinosoft Business Solutions Dinosoft ERP allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Dinosoft ERP: from < 3.0.1 through 11022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Title Improper Access Control in Dinosoft Business Solutions' Dinosoft ERP
Weaknesses CWE-284
CWE-306
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Dinosoft Business Solutions Dinosoft Erp
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-03-25T14:07:20.222Z

Reserved: 2025-07-22T08:54:05.418Z

Link: CVE-2025-8025

cve-icon Vulnrichment

Updated: 2026-02-11T14:38:18.351Z

cve-icon NVD

Status : Deferred

Published: 2026-02-11T13:15:58.777

Modified: 2026-04-15T00:35:42.020

Link: CVE-2025-8025

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-02-11T21:38:24Z

Weaknesses