Description
Chiline Cloud developed by Inventec Appliances has a Insecure Direct Object Reference vulnerability. Unauthenticated remote attackers can modify a specific parameter to read other users' sensitive data.
Published: 2026-08-11
Score: 8.7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Chiline Cloud, developed by Inventec Appliances, has an insecure direct object reference vulnerability that allows unauthenticated remote attackers to alter a specific parameter and read other users' sensitive data. The flaw, identified as CWE‑639, can lead to unauthorized disclosure of confidential information. This attack does not modify data or grant code execution, but it exposes sensitive data that could be used for further exploitation.

Affected Systems

The vulnerability affects the Inventec Appliances Chiline Cloud platform. No specific affected product versions are listed in the advisory, and version details are not available in the supplied data.

Risk and Exploitability

The vulnerability has a CVSS score of 8.7, indicating a high severity impact. The EPSS score is not available, and the issue is not listed in CISA's KEV catalog. Attackers can exploit the flaw remotely and unauthenticated by manipulating a URL or API parameter that accesses user data. The service provider has resolved the issue at the cloud level, so customers are not required to take action.

Generated by OpenCVE AI on August 11, 2026 at 03:50 UTC.

Remediation

Vendor Solution

The service provider has resolved the vulnerability at the cloud level; no customer action is required


OpenCVE Recommended Actions

  • No customer action is required; the service provider has resolved the vulnerability at the cloud level.
  • Implement strict authorization checks on all API endpoints that expose user data to ensure that requests are bound to the authenticated user’s identity.
  • Add input validation and sanitization for object identifiers; reject any that do not conform to expected formats or do not belong to the requesting user.

Generated by OpenCVE AI on August 11, 2026 at 03:50 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
First Time appeared Inventec Appliances
Inventec Appliances chiline Cloud
Vendors & Products Inventec Appliances
Inventec Appliances chiline Cloud

Tue, 11 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Description Chiline Cloud developed by Inventec Appliances has a Insecure Direct Object Reference vulnerability. Unauthenticated remote attackers can modify a specific parameter to read other users' sensitive data.
Title Inventec Appliances|Chiline Cloud - Insecure Direct Object Reference
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Inventec Appliances Chiline Cloud
cve-icon MITRE

Status: PUBLISHED

Assigner: twcert

Published:

Updated: 2026-08-12T18:31:36.411Z

Reserved: 2026-08-10T11:31:22.446Z

Link: CVE-2026-19424

cve-icon Vulnrichment

Updated: 2026-08-12T18:30:11.892Z

cve-icon NVD

Status : Deferred

Published: 2026-08-11T03:17:36.157

Modified: 2026-08-26T16:40:21.650

Link: CVE-2026-19424

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T14:20:16Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key