Description
Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained by ACLs.

This issue affects Liman MYS: from 2.2.3 before 2.3.1.
Published: 2026-08-04
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization flaw in HAVELSAN's Liman MYS application, allowing attackers to access protected functionality without the required permissions. This flaw is categorized as a lack of proper access control (CWE‑862) and can be exploited to read or manipulate data that should only be available to authorized users. The primary impact is unauthorized data access or potential privilege escalation within the system, as sensitive operations can be performed by users who do not have the correct ACL entries.

Affected Systems

The flaw affects Liman MYS deployments with versions from 2.2.3 up to, but not including, 2.3.1. Users running any of those releases are potentially exposed, while versions 2.3.1 and later contain the fix. The vendor product is identified as HAVELSAN Inc.'s Liman MYS, a management system for ...

Risk and Exploitability

The CVSS base score is 8.8, indicating a high severity. The EPSS score is not reported, so precise likelihood of exploitation cannot be quantified, but the absence of KEV status suggests no currently known public exploitation. The attack vector requires the attacker to reach the application layer, either through an authenticated session or by invoking exposed endpoints that lack proper ACL checks. Once a user has network or local access to the system, the missing authorization can be leveraged, making the vulnerability particularly dangerous if internal users are compromised.

Generated by OpenCVE AI on August 4, 2026 at 19:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Liman MYS to version 2.3.1 or later, which contains the authorization fix.
  • If an upgrade is not immediately possible, restrict access to the affected modules by applying network or application‑level access controls so that only trusted users can reach the vulnerable functionality.
  • Review and reinforce ACL configurations to ensure that all privileged operations require explicit permission checks, consistent with CWE‑862 best practices.
  • Monitor logs for unauthorized activity and conduct periodic security testing to confirm that the access controls are enforced.

Generated by OpenCVE AI on August 4, 2026 at 19:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 17:15:00 +0000

Type Values Removed Values Added
First Time appeared Havelsan
Havelsan liman Mys
Vendors & Products Havelsan
Havelsan liman Mys

Tue, 04 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 14:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Liman MYS: from 2.2.3 before 2.3.1.
Title Vault Credential Confusion via Authorization Bypass in HAVELSAN's Liman MYS
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Havelsan Liman Mys
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-08-04T15:34:21.173Z

Reserved: 2026-07-24T14:07:35.502Z

Link: CVE-2026-17070

cve-icon Vulnrichment

Updated: 2026-08-04T15:34:16.801Z

cve-icon NVD

Status : Received

Published: 2026-08-04T14:16:30.733

Modified: 2026-08-04T16:16:21.230

Link: CVE-2026-17070

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T20:00:05Z

Weaknesses