Description
An issue in GAPTEQ Designer v.3.5 allows a remote attacker to escalate privileges via the Company Manger role.
Published: 2026-08-17
Score: 9.8 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in GAPTEQ Designer v3.5 allows a remote attacker to elevate privileges by leveraging the Company Manager role. This flaw gives users non‑privileged access an administrative level, enabling them to perform actions that should be restricted. By gaining such privileges, an attacker could compromise confidentiality, integrity, and availability of the application and potentially the underlying systems. The weakness is a classic case of improper authorization (CWE‑269).

Affected Systems

Products affected are GAPTEQ Designer version 3.5. No specific sub‑version or patch level information is provided, so all releases of v3.5 are potentially impacted.

Risk and Exploitability

Based on the provided information, the vulnerability in GAPTEQ Designer v3.5 carries a CVSS score of 9.8, indicating critical severity. The EPSS score of less than 1% suggests a low probability of exploitation, and the vulnerability is not listed in the CISA Known Exploited Vulnerabilities catalog. Attackers can remotely exploit the flaw to elevate privileges to the Company Manager role, potentially gaining full administrative control and compromising the confidentiality, integrity, and availability of the system. Since the description does not specify authentication prerequisites, it is possible that the exploit could be carried out by unauthenticated network users; however, the exact attack vector remains unspecified in the CVE details.

Generated by OpenCVE AI on August 21, 2026 at 20:29 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest vendor patch for GAPTEQ Designer v3.5 when it becomes available
  • Limit the use of the Company Manager role to a minimal set of trusted users
  • If the Company Manager role is not required, disable or remove it from the system configuration
  • Monitor application logs for anomalous privilege escalation attempts

Generated by OpenCVE AI on August 21, 2026 at 20:29 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 21 Aug 2026 20:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Company Manager Role in GAPTEQ Designer 3.5

Tue, 18 Aug 2026 23:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Company Manager Role in GAPTEQ Designer
Weaknesses CWE-285

Tue, 18 Aug 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 17 Aug 2026 20:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Company Manager Role in GAPTEQ Designer
Weaknesses CWE-285

Mon, 17 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
Description An issue in GAPTEQ Designer v.3.5 allows a remote attacker to escalate privileges via the Company Manger role.
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-08-18T18:24:14.278Z

Reserved: 2026-06-07T00:00:00.000Z

Link: CVE-2026-50774

cve-icon Vulnrichment

Updated: 2026-08-18T18:23:09.938Z

cve-icon NVD

Status : Received

Published: 2026-08-17T19:16:31.767

Modified: 2026-08-18T19:16:55.440

Link: CVE-2026-50774

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-21T20:30:07Z

Weaknesses
  • CWE-269

    Improper Privilege Management