Description
An issue in GAPTEQ Designer v.3.5 allows a remote attacker to escalate privileges via the Company Manger role.
Published: 2026-08-17
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An issue in GAPTEQ Designer v3.5 allows a remote attacker to elevate privileges through the Company Manager role. The flaw enables non‑privileged users to gain administrative permissions within the application, compromising confidentiality, integrity, and availability of the system. This is a classic example of improper authorization where the application does not correctly validate user roles before granting access to privileged functions.

Affected Systems

Products affected are GAPTEQ Designer version 3.5. No specific sub‑version or patch level information is provided, so all releases of v3.5 are potentially impacted.

Risk and Exploitability

The vulnerability can be exploited over the network by an attacker who can access the application. There is no EPSS score available and the issue is not listed in the CISA KEV catalog, so the exact likelihood of exploitation is unknown, but the potential to elevate privileges to a Company Manager role carries a high risk. Attackers would need to authenticate with a compromised or low‑privileged account and then trigger the privilege escalation path described in the product’s design.

Generated by OpenCVE AI on August 17, 2026 at 19:34 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest vendor patch for GAPTEQ Designer v3.5 when it becomes available
  • Limit the use of the Company Manager role to a minimal set of trusted users
  • If the Company Manager role is not required, disable or remove it from the system configuration
  • Monitor application logs for anomalous privilege escalation attempts

Generated by OpenCVE AI on August 17, 2026 at 19:34 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 17 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Company Manager Role in GAPTEQ Designer
Weaknesses CWE-285

Mon, 17 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Description An issue in GAPTEQ Designer v.3.5 allows a remote attacker to escalate privileges via the Company Manger role.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-17T18:08:16.798Z

Reserved: 2026-06-07T00:00:00.000Z

Link: CVE-2026-50774

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-17T19:16:31.767

Modified: 2026-08-17T19:16:31.767

Link: CVE-2026-50774

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-17T19:45:04Z

Weaknesses