Impact
An incorrect authorization check in Turboard FOR‑S can be abused to elevate privileges. Exploiting this flaw allows an attacker with any user or local access to obtain higher‑level permissions or full control over the application, potentially compromising confidential data or disrupting services. The weakness is classified as CWE‑863, reflecting an implicit or missing authorization validation.
Affected Systems
The vulnerability affects E‑Kalite Software Hardware Engineering Design and Internet Services Industry and Trade Ltd. Co.'s Turboard FOR‑S product, specifically versions starting with 7.01.2026 up to, but not including, 18.02.2026. All later releases are presumed fixed.
Risk and Exploitability
With a CVSS score of 8.8, this issue is considered high severity. The EPSS score is not available, so the precise exploitation likelihood is uncertain, yet the lack of a KEV listing does not reduce the risk; the flaw permits privilege escalation potentially through the application interface. Based on the description, the attack vector is likely local or on‑premises, but could extend remotely if network access to the system is possible. Attacks would require exploiting the bug to bypass authorization checks, making it a significant threat to privileged users and the integrity of the system.
OpenCVE Enrichment