Impact
The vulnerability arises from improper validation of a specific type of input in Magarsus Consulting Ltd. Co.'s IDM‑MFA, corresponding to CWE‑1287, allowing an attacker to bypass the OTP authentication step and gain unauthorized access to protected resources. This authentication bypass directly undermines the confidentiality and integrity of systems relying on the product and can let any user assume privileged roles if they can exploit the input flaw.
Affected Systems
Affected systems are Magarsus Consulting Ltd. Co.'s IDM‑MFA product series, specifically versions released on or after November 27, 2025 and before March 10, 2026. The product name is IDM‑MFA and the vendor is Magarsus Consulting Ltd. Co.
Risk and Exploitability
The vulnerability’s CVSS score of 8.1 indicates high severity, but its EPSS score is less than 1%, suggesting a low probability of exploitation in the wild as of the current data. It is not listed in the CISA KEV catalog. The attack vector is not explicitly documented; based on the description it is inferred that the attacker might exploit the flaw by submitting crafted input during the OTP verification phase, potentially from a remote or local context. This flaw is classified as CWE‑1287, an input validation issue. The lack of a public patch or CNA workaround currently means the risk remains until an official fix is released.
OpenCVE Enrichment