Description
Insertion of sensitive information into sent data vulnerability in Sayax Energy Technologies Inc. OSOS allows Authentication Bypass.

This issue affects OSOS: through 09072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-07-09
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability (CWE‑201) allows sensitive information to be inserted into outgoing data, enabling an attacker to bypass authentication and gain unauthorized access to protected resources. This results in a potential compromise of confidentiality and integrity of the system’s data.

Affected Systems

Sayax Energy Technologies Inc. OSOS, affected through version 09072026.

Risk and Exploitability

The CVSS score of 6.5 indicates a medium severity, while the EPSS score of less than 1% suggests a very low current exploitation probability. The vulnerability is not listed in the CISA KEV catalog, and the vendor has not yet released a fix. Based on the description, it is inferred that the attack vector is remote via network traffic that carries the inserted sensitive data. Overall, the risk is moderate due to the moderate severity, but the low exploitation likelihood reduces the immediate threat level.

Generated by OpenCVE AI on July 28, 2026 at 08:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Contact Sayax Energy Technologies for an update or patch when it becomes available
  • Disable or restrict the functionality that transmits sensitive data to prevent the insertion of sensitive information
  • Configure network filtering or IDS/IPS rules to block payloads containing the inserted data
  • Continuously monitor authentication logs for suspicious activity and investigate any unauthorized access attempts

Generated by OpenCVE AI on July 28, 2026 at 08:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Sayax
Sayax osos
Vendors & Products Sayax
Sayax osos

Thu, 09 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Description Insertion of sensitive information into sent data vulnerability in Sayax Energy Technologies Inc. OSOS allows Authentication Bypass. This issue affects OSOS: through 09072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Title Information Disclosure in Sayax's OSOS
Weaknesses CWE-201
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-07-09T12:35:01.242Z

Reserved: 2026-01-23T08:12:17.605Z

Link: CVE-2026-1365

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-28T09:00:06Z

Weaknesses
  • CWE-201

    Insertion of Sensitive Information Into Sent Data