Description
Missing Authorization vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs.

This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.
Published: 2026-07-17
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Vimesoft Inc. Enterprise Video Platform suffers from a missing authorization vulnerability (CWE-862) that permits attackers to invoke restricted functionalities which should be protected by access control lists. This flaw allows unauthorized exploitation of platform features that are not properly constrained by ACLs, creating a window for abuse of protected operations.

Affected Systems

The vulnerability impacts Vimesoft Inc. Enterprise Video Platform versions 3.11.0.0 through, but not including, 3.25.0. Administrators should verify that installed instances fall within this range.

Risk and Exploitability

The CVSS score of 9.1 indicates a high severity, and the EPSS score of less than 1% suggests a low but non-zero likelihood of exploitation at present. The issue is not listed in the CISA KEV catalog. While the CVE description does not specify an attack vector, it is inferred that remote exploitation is possible through the platform’s network interfaces, provided the attacker can reach the service.

Generated by OpenCVE AI on August 1, 2026 at 08:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑issued update addressing the missing authorization checks.
  • If an immediate update is unavailable, limit access to the platform to trusted users or network segments to reduce exposure.
  • Disable or lock the functionality that is affected by the missing authorization checks until a patch is applied.

Generated by OpenCVE AI on August 1, 2026 at 08:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Vimesoft
Vimesoft enterprise Video Platform
Vendors & Products Vimesoft
Vimesoft enterprise Video Platform

Fri, 17 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Vimesoft Inc. Enterprise Video Platform allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Enterprise Video Platform: from 3.11.0.0 before 3.25.0.
Title Missing Authorization in Vimesoft's Enterprise Video Platform
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H'}


Subscriptions

Vimesoft Enterprise Video Platform
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-07-17T17:54:58.489Z

Reserved: 2026-06-19T09:01:28.607Z

Link: CVE-2026-12694

cve-icon Vulnrichment

Updated: 2026-07-17T17:54:54.821Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-01T08:30:03Z

Weaknesses