Description
Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Privilege Escalation.

This issue affects Liman MYS: from 2.2.3 before 2.3.1.
Published: 2026-08-04
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a missing authorization flaw that allows an attacker to elevate privileges and execute arbitrary code at the system level. Because the authorization check is absent, a user can gain root-level access and compromise confidentiality, integrity, and availability of the affected system. The weakness is identified as CWE-862.

Affected Systems

HAVELSAN Inc. Liman MYS, versions from 2.2.3 up to but not including 2.3.1.

Risk and Exploitability

The CVSS score of 8.8 indicates a high severity of this issue. EPSS is not available, so the exact exploitation likelihood is unknown, and the vulnerability is not listed in CISA's KEV catalog. The missing authorization check suggests that the vulnerability can be exploited without authentication, likely via remote or local access to the Liman MYS interface. An attacker with the ability to interact with the application can gain full root privileges, making this a high‑risk threat to affected deployments.

Generated by OpenCVE AI on August 4, 2026 at 19:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Liman MYS to version 2.3.1 or later to apply the vendor’s fix for the missing authorization check.
  • If an upgrade cannot be performed immediately, limit network exposure of the application or place the service behind a stricter authentication gateway to restrict unauthenticated users from reaching the vulnerable component.
  • Apply any vendor‑provided configuration guidance that enforces least privilege for the application process and monitor system logs for suspicious activity indicative of privilege escalation attempts.

Generated by OpenCVE AI on August 4, 2026 at 19:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Havelsan
Havelsan liman Mys
Vendors & Products Havelsan
Havelsan liman Mys

Tue, 04 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 04 Aug 2026 15:00:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Privilege Escalation. This issue affects Liman MYS: from 2.2.3 before 2.3.1.
Title Missing Authorization Leading to Root Code Execution in HAVELSAN's Liman MYS
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Havelsan Liman Mys
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-08-04T15:37:01.395Z

Reserved: 2026-08-03T11:36:26.396Z

Link: CVE-2026-18650

cve-icon Vulnrichment

Updated: 2026-08-04T15:36:40.700Z

cve-icon NVD

Status : Received

Published: 2026-08-04T15:16:31.410

Modified: 2026-08-04T17:16:46.880

Link: CVE-2026-18650

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T20:00:05Z

Weaknesses