Description
Authorization bypass through User-Controlled key vulnerability in PAVO Financial Technology Solutions Inc. PAVO Pay allows Exploitation of Trusted Identifiers.

This issue affects PAVO Pay: through 09072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-07-09
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an information disclosure and control flaw that allows an authenticated user to supply a user‑controlled key and bypass PAVO Pay’s authorization checks. By presenting a trusted identifier that does not belong to them, an attacker can access data or perform actions reserved for the legitimate owner, leading to unauthorized information disclosure or transaction manipulation. The flaw is classified as CWE‑639, an authorization bypass through a user‑controlled key.

Affected Systems

The vulnerability affects PAVO Financial Technology Solutions Inc.’s PAVO Pay product. Versions up to and including 09072026 are vulnerable; no other vendors or products are listed.

Risk and Exploitability

The CVSS score of 7.5 indicates a high severity. The EPSS score of less than 1% suggests that the likelihood of exploitation in the wild is low at present. The vulnerability is not listed in CISA’s KEV catalog, implying it has not yet been widely exploited. The likely attack vector is inferred to be via manipulated HTTP requests where the user supplies a user‑controlled key; the lack of an explicit description leaves the exact exploitation pathway unspecified, but typical IDOR behavior would apply.

Generated by OpenCVE AI on July 29, 2026 at 12:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest PAVO Pay release that removes the user‑controlled key authorization binding to the authenticated session, rejecting any mismatched keys.
  • Enable logging and monitoring for unusual identifier usage and investigate any indications of unauthorized access.
  • Audit current user identifiers and enforce that each key is properly bound to its owning user to prevent cross‑user access.

Generated by OpenCVE AI on July 29, 2026 at 12:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 11 Jul 2026 03:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Pavo
Pavo pavo Pay
Vendors & Products Pavo
Pavo pavo Pay

Thu, 09 Jul 2026 09:30:00 +0000

Type Values Removed Values Added
Description Authorization bypass through User-Controlled key vulnerability in PAVO Financial Technology Solutions Inc. PAVO Pay allows Exploitation of Trusted Identifiers. This issue affects PAVO Pay: through 09072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Title IDOR in PAVO Inc.'s PAVO Pay
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-07-09T12:33:51.423Z

Reserved: 2026-02-05T15:22:11.030Z

Link: CVE-2026-1989

cve-icon Vulnrichment

Updated: 2026-07-09T12:33:46.719Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T12:45:03Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key