Description
Authorization bypass through User-Controlled key vulnerability in TECHIN2B TECHIN2B Application allows Privilege Abuse.

This issue affects TECHIN2B Application: from V1.0.7676.13 through 18092026.
NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-09-18
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Assess Impact
AI Analysis

Impact

Authorization bypass through a user‑controlled key in the TECHIN2B Application permits an attacker to elevate privileges beyond what is normally allowed. This weakness is a classic broken access control flaw and can compromise the confidentiality, integrity, and availability of data and systems by allowing unauthenticated or low‑privileged users to perform actions reserved for higher‑privileged accounts.

Affected Systems

The flaw affects TECHIN2B Application versions from V1.0.7676.13 up to at least 18092026. Any installation of the application in this version range is susceptible.

Risk and Exploitability

The vulnerability carries a CVSS score of 8.8, classifying it as high severity, yet the EPSS indicates a very low probability of exploitation at this time. It is not listed in CISA’s KEV catalog, suggesting no known active exploits. The likely attack vector is remote, inferred from the user‑controlled key input that can be manipulated over the network, but the description does not explicitly state the method of exploitation.

Generated by OpenCVE AI on September 19, 2026 at 20:17 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Enforce strict role‑based access controls and remove any unneeded privileged accounts
  • Apply network segmentation to limit user reach to sensitive components of the application
  • Widely log and monitor authentication attempts and privileged actions to detect potential abuse
  • Contact the vendor and demand a patch or a temporary fix, and consider disabling the affected functionality until a vendor response is received
  • Implement application layer controls to validate or sanitize any user‑supplied keys used in authorization logic

Generated by OpenCVE AI on September 19, 2026 at 20:17 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 19 Sep 2026 23:00:00 +0000

Type Values Removed Values Added
First Time appeared Techin2b
Techin2b techin2b Application
Vendors & Products Techin2b
Techin2b techin2b Application

Fri, 18 Sep 2026 21:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 18 Sep 2026 08:00:00 +0000

Type Values Removed Values Added
Description Authorization bypass through User-Controlled key vulnerability in TECHIN2B TECHIN2B Application allows Privilege Abuse. This issue affects TECHIN2B Application: from V1.0.7676.13 through 18092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Title Broken Access Control in TECHIN2B Application
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Techin2b Techin2b Application
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-09-18T19:16:03.483Z

Reserved: 2026-06-16T10:44:20.111Z

Link: CVE-2026-12384

cve-icon Vulnrichment

Updated: 2026-09-18T19:15:58.018Z

cve-icon NVD

Status : Deferred

Published: 2026-09-18T08:16:58.813

Modified: 2026-09-18T20:17:04.707

Link: CVE-2026-12384

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-19T22:30:13Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key