Description
Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained by ACLs.

This issue affects Liman MYS: before release.Master.1107.
Published: 2026-07-07
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability occurs because the application does not enforce access control lists on certain functions, allowing unauthorized users to execute restricted operations. This flaw permits accessing functionality not properly constrained by ACLs. The weakness is identified as an authorization bypass, classified by CWE-862.

Affected Systems

The affected product is the Liman MYS system from HAVELSAN Inc. Version strings prior to the release identified as Master.1107 are impacted. No other vendors or versions are listed.

Risk and Exploitability

With a CVSS score of 8.3, the severity is considered High. The EPSS score is less than 1%, indicating low exploitation probability. The vulnerability is not listed in the CISA KEV catalog. Based on the description, it is inferred that the potential attack vector is through application interfaces where authorization checks are omitted, which may be reachable by users with or without credentials.

Generated by OpenCVE AI on July 26, 2026 at 19:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Liman MYS to a release newer than Master.1107 where the authorization checks are fixed.
  • Review and ensure that all API endpoints and UI actions enforce role-based access control and validate ACL entries before executing sensitive logic.
  • Implement monitoring on authentication and authorization logs to detect and alert on any abnormal access patterns that may indicate exploitation of this flaw available patches or guidance.

Generated by OpenCVE AI on July 26, 2026 at 19:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Havelsan
Havelsan liman Mys
Vendors & Products Havelsan
Havelsan liman Mys

Tue, 07 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 07 Jul 2026 11:15:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Liman MYS: before release.Master.1107.
Title Authorization Bypass in HAVELSAN's Open Source Project Liman MYS
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:H'}


Subscriptions

Havelsan Liman Mys
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-07-07T12:05:14.017Z

Reserved: 2026-06-05T08:19:03.687Z

Link: CVE-2026-11340

cve-icon Vulnrichment

Updated: 2026-07-07T12:05:05.886Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T19:30:03Z

Weaknesses