Impact
The vulnerability is an IDOR that allows an attacker to use a user‑controlled key to access functionality that is not properly constrained by ACLs. This flaw enables unauthorized users to invoke privileged operations and potentially view or manipulate sensitive data. The weakness, identified as CWE-639, can lead to confidentiality and integrity violations.
Affected Systems
Affected systems include AKIN Software’s OctoCloud product. Any deployment running version 1.12.06 or earlier is vulnerable. The product is identified by the vendor AKIN Software Computer Import‑Export Industry and Trade Co. Ltd., and the specific impacted releases are those before 1.12.07.
Risk and Exploitability
The CVSS score of 8.8 demonstrates a high severity, while no EPSS score is available. The vulnerability is not listed in the CISA KEV catalog. A typical exploitation path would involve an authenticated user supplying a crafted key to reach the protected function, bypassing normal ACL checks. Because the flaw is classic IDOR, it is likely to be exploitable with minimal privilege, making it a significant risk for systems lacking additional safeguards.
OpenCVE Enrichment