Description
A vulnerability was found in datadrivenconstruction OpenConstructionERP up to 14.8.1. The impacted element is an unknown function of the file backend/app/modules/ai/ai_client.py of the component Al Provider Configuration Handler. Performing a manipulation results in exposure of data element to wrong session. The attack may be initiated remotely. The exploit has been made public and could be used. Upgrading to version 15.0.0 is sufficient to resolve this issue. It is suggested to upgrade the affected component.
Published: 2026-10-01
Score: 5.3 Medium
EPSS: n/a
KEV: No
Impact: Unauthorized Data Exposure
Action: Apply Patch
AI Analysis

Impact

A flaw in the AI Provider Configuration Handler of OpenConstructionERP allows an attacker to manipulate session data, causing sensitive information to be exposed to the wrong user session. This weakness is classified as CWE-488, an improper locking issue, where lack of proper session isolation leads to unauthorized data leakage. The vulnerability can potentially grant an adversary access to confidential data that should be restricted to a specific user context.

Affected Systems

OpenConstructionERP from datadrivenconstruction is affected in all releases up to and including version 14.8.1. Users running these versions have been identified as vulnerable; the problem is fixed in version 15.0.0.

Risk and Exploitability

The CVSS score of 5.3 indicates a moderate severity, and the EPSS score is not available, suggesting no data on current exploitation probability, but the flaw is publicly documented and can be triggered remotely. The vulnerability is not listed in the CISA KEV catalog, yet it has been disclosed publicly. The likely attack vector is remote exploitation across the network, potentially by sending crafted inputs to the AI provider endpoint to cause session data leakage.

Generated by OpenCVE AI on October 1, 2026 at 07:33 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade OpenConstructionERP to at least version 15.0.0 to eliminate the session‑mismanagement flaw.
  • After upgrading, verify that the AI Provider Configuration Handler correctly isolates session data between distinct users.
  • Continuously monitor authentication and data‑access logs for signs of anomalous session behavior that might indicate residual exposure.

Generated by OpenCVE AI on October 1, 2026 at 07:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 06:45:00 +0000

Type Values Removed Values Added
Description A vulnerability was found in datadrivenconstruction OpenConstructionERP up to 14.8.1. The impacted element is an unknown function of the file backend/app/modules/ai/ai_client.py of the component Al Provider Configuration Handler. Performing a manipulation results in exposure of data element to wrong session. The attack may be initiated remotely. The exploit has been made public and could be used. Upgrading to version 15.0.0 is sufficient to resolve this issue. It is suggested to upgrade the affected component.
Title datadrivenconstruction OpenConstructionERP Al Provider Configuration ai_client.py wrong session
First Time appeared Datadrivenconstruction
Datadrivenconstruction openconstructionerp
Weaknesses CWE-488
CPEs cpe:2.3:a:datadrivenconstruction:openconstructionerp:*:*:*:*:*:*:*:*
Vendors & Products Datadrivenconstruction
Datadrivenconstruction openconstructionerp
References
Metrics cvssV2_0

{'score': 6.5, 'vector': 'AV:N/AC:L/Au:S/C:P/I:P/A:P/E:POC/RL:OF/RC:C'}

cvssV3_0

{'score': 6.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV3_1

{'score': 6.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C'}

cvssV4_0

{'score': 5.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

Datadrivenconstruction Openconstructionerp
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-10-01T06:15:12.332Z

Reserved: 2026-09-30T19:08:00.662Z

Link: CVE-2026-103544

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-01T07:16:33.900

Modified: 2026-10-01T07:16:33.900

Link: CVE-2026-103544

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T07:45:04Z

Weaknesses
  • CWE-488

    Exposure of Data Element to Wrong Session