Impact
Authorization bypass through a user‑controlled key in the TECHIN2B Application permits an attacker to elevate privileges beyond what is normally allowed. This weakness is a classic broken access control flaw and can compromise the confidentiality, integrity, and availability of data and systems by allowing unauthenticated or low‑privileged users to perform actions reserved for higher‑privileged accounts.
Affected Systems
The flaw affects TECHIN2B Application versions from V1.0.7676.13 up to at least 18092026. Any installation of the application in this version range is susceptible.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.8, classifying it as high severity, yet the EPSS indicates a very low probability of exploitation at this time. It is not listed in CISA’s KEV catalog, suggesting no known active exploits. The likely attack vector is remote, inferred from the user‑controlled key input that can be manipulated over the network, but the description does not explicitly state the method of exploitation.
OpenCVE Enrichment