Impact
The vulnerability in IKAS Technology’s Rush allows an unauthenticated API endpoint to be used to fake the source of analytics data. This flaw means that an attacker who can reach the API can send requests that override legitimate data, thereby compromising the integrity of analytics reports and any decisions based upon them, while the attacker remains invisible to authentication controls.
Affected Systems
IKAS Technology Inc. Rush, versions through 21082026, is affected. The vulnerability manifests in any installation of Rush that has not been upgraded beyond the 21082026 release, regardless of deployment environment.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score of 0.00314 indicates a very low exploitation probability. Because the flaw is unauthenticated, the attack vector is likely over an exposed network interface or web service. The vulnerability is not listed in the CISA KEV catalog, so no active widespread exploitation evidence is reported. Nonetheless, an attacker who can reach the API can manipulate analytics data with low effort.
OpenCVE Enrichment