Description
A weakness has been identified in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. This affects an unknown part. This manipulation causes missing authentication. The attack is possible to be carried out remotely. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-07-12
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in RafyMrX TOKO-ONLINE-ROTI allows an attacker to bypass authentication controls, leading to unauthorized access to the application’s functions. It originates from a flaw that causes missing authentication, enabling remote exploitation. The weakness falls under CWE‑287 (Improper Authentication) and CWE‑306 (Missing Authentication).

Affected Systems

The affected product is RafyMrX TOKO-ONLINE-ROTI. No specific version numbers are listed because the vendor’s rolling release strategy prevents precise mapping; the vulnerability may exist in any recent or unreleased commit. Administrators must therefore consider all current builds of the application as potentially impacted until a vendor‑issued fix or version upgrade is released.

Risk and Exploitability

This vulnerability has a CVSS score of 6.9, classifying it as moderate. The EPSS score of less than 1% indicates a low probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog. The description states that the attack can be carried out remotely, so the likely attack vector is remote. If exploited, an attacker could gain unauthorized access to the application’s backend.

Generated by OpenCVE AI on July 29, 2026 at 08:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Install vendor patches that address improper authentication (CWE-287) and missing authentication (CWE-306).
  • Restrict the application’s network reach to trusted hosts using firewall rules or VPNs to limit remote exploitation.
  • Continuously monitor vendor advisories and deploy newer releases that remove the authentication bypass when available.

Generated by OpenCVE AI on July 29, 2026 at 08:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 14 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Sun, 12 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description A weakness has been identified in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. This affects an unknown part. This manipulation causes missing authentication. The attack is possible to be carried out remotely. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The vendor was contacted early about this disclosure but did not respond in any way.
Title RafyMrX TOKO-ONLINE-ROTI missing authentication
First Time appeared Rafymrx
Rafymrx toko-online-roti
Weaknesses CWE-287
CWE-306
CPEs cpe:2.3:a:rafymrx:toko-online-roti:*:*:*:*:*:*:*:*
Vendors & Products Rafymrx
Rafymrx toko-online-roti
References
Metrics cvssV2_0

{'score': 7.5, 'vector': 'AV:N/AC:L/Au:N/C:P/I:P/A:P/E:ND/RL:ND/RC:UR'}

cvssV3_0

{'score': 7.3, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R'}

cvssV3_1

{'score': 7.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:X/RC:R'}

cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X'}


Subscriptions

Rafymrx Toko-online-roti
cve-icon MITRE

Status: PUBLISHED

Assigner: VulDB

Published:

Updated: 2026-07-14T14:41:07.744Z

Reserved: 2026-07-11T11:58:42.133Z

Link: CVE-2026-15491

cve-icon Vulnrichment

Updated: 2026-07-14T14:41:00.934Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T09:00:18Z

Weaknesses
  • CWE-287

    Improper Authentication

  • CWE-306

    Missing Authentication for Critical Function