Description
Authorization bypass through User-Controlled key vulnerability in Netiket Information Technologies EdoWEB allows Accessing Functionality Not Properly Constrained by ACLs.

This issue affects EdoWEB: before 780-g7.
Published: 2026-08-18
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Netiket Information Technologies EdoWEB suffers from an IDOR flaw in which a user‑controlled key bypasses ACL checks, allowing an attacker to invoke protected functionality that should be restricted. The vulnerability, classified as CWE‑639, can lead to unauthorized actions or exposure of sensitive data within the application.

Affected Systems

The affected product is Netiket Information Technologies EdoWEB. Versions prior to 780‑g7 contain the flaw; the patch is included in release 780‑g7 and later.

Risk and Exploitability

The CVSS base score of 5.3 denotes a moderate severity, but the EPSS score is unavailable and the issue is not listed in the CISA KEV catalog, indicating no known active exploits. It is inferred that the attack vector is a web request where an attacker manipulates the key parameter to gain unauthorized access. Given its moderate severity and potential for privilege escalation, monitoring and timely remediation are advised.

Generated by OpenCVE AI on August 18, 2026 at 14:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to EdoWEB version 780‑g7 or newer to address the IDOR flaw
  • Block or restrict access to the API endpoints that use the vulnerable key parameter until the upgrade can be applied
  • Continuously monitor application logs for unauthorized requests using the key parameter and investigate any suspicious activity

Generated by OpenCVE AI on August 18, 2026 at 14:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 13:00:00 +0000

Type Values Removed Values Added
First Time appeared Netiket Information Technologies
Netiket Information Technologies edoweb
Vendors & Products Netiket Information Technologies
Netiket Information Technologies edoweb

Tue, 18 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 18 Aug 2026 13:15:00 +0000

Type Values Removed Values Added
Description Authorization bypass through User-Controlled key vulnerability in Netiket Information Technologies EdoWEB allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects EdoWEB: before 780-g7.
Title IDOR in Netiket Information Technologies' EdoWEB
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Netiket Information Technologies Edoweb
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-08-18T16:02:40.484Z

Reserved: 2026-07-20T14:33:14.920Z

Link: CVE-2026-16309

cve-icon Vulnrichment

Updated: 2026-08-18T16:02:36.983Z

cve-icon NVD

Status : Deferred

Published: 2026-08-18T13:17:20.140

Modified: 2026-08-26T16:51:19.490

Link: CVE-2026-16309

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T12:39:11Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key