Description
Missing authentication for critical function vulnerability in IKAS Technology Inc. Rush allows Fake the Source of Data.

This issue affects Rush: through 21082026. 
NOTE: The vendor was contacted and it was learned that the product is not supported.
Published: 2026-08-21
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Data Integrity Compromise
Action: Restrict Access
AI Analysis

Impact

The vulnerability in IKAS Technology’s Rush allows an unauthenticated API endpoint to be used to fake the source of analytics data. This flaw means that an attacker who can reach the API can send requests that override legitimate data, thereby compromising the integrity of analytics reports and any decisions based upon them, while the attacker remains invisible to authentication controls.

Affected Systems

IKAS Technology Inc. Rush, versions through 21082026, is affected. The vulnerability manifests in any installation of Rush that has not been upgraded beyond the 21082026 release, regardless of deployment environment.

Risk and Exploitability

The CVSS score of 5.3 indicates moderate severity, and the EPSS score of 0.00314 indicates a very low exploitation probability. Because the flaw is unauthenticated, the attack vector is likely over an exposed network interface or web service. The vulnerability is not listed in the CISA KEV catalog, so no active widespread exploitation evidence is reported. Nonetheless, an attacker who can reach the API can manipulate analytics data with low effort.

Generated by OpenCVE AI on August 27, 2026 at 19:10 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Implement network restrictions to limit the Rush API to trusted hosts or firewall ACLs
  • Add custom authentication logic or input validation to the API to enforce access control
  • Configure monitoring to detect anomalies in analytics data outputs

Generated by OpenCVE AI on August 27, 2026 at 19:10 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 27 Aug 2026 16:45:00 +0000

Type Values Removed Values Added
Description Missing authentication for critical function vulnerability in IKAS Technology Inc. Rush allows Fake the Source of Data. This issue affects Rush: through 21082026. Missing authentication for critical function vulnerability in IKAS Technology Inc. Rush allows Fake the Source of Data. This issue affects Rush: through 21082026.  NOTE: The vendor was contacted and it was learned that the product is not supported.

Fri, 21 Aug 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 21 Aug 2026 12:30:00 +0000

Type Values Removed Values Added
First Time appeared Ikas Technology
Ikas Technology rush
Vendors & Products Ikas Technology
Ikas Technology rush

Fri, 21 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
Description Missing authentication for critical function vulnerability in IKAS Technology Inc. Rush allows Fake the Source of Data. This issue affects Rush: through 21082026.
Title Unauthenticated API Allows Analytics Data Manipulation in IKAS Technology's Rush
Weaknesses CWE-306
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N'}


Subscriptions

Ikas Technology Rush
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-08-27T13:37:13.859Z

Reserved: 2026-08-10T13:24:37.166Z

Link: CVE-2026-19441

cve-icon Vulnrichment

Updated: 2026-08-21T12:39:59.791Z

cve-icon NVD

Status : Deferred

Published: 2026-08-21T08:16:43.837

Modified: 2026-08-27T17:17:37.493

Link: CVE-2026-19441

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-27T19:15:03Z

Weaknesses
  • CWE-306

    Missing Authentication for Critical Function