Description
An issue in Invixium IXM WEB v.2.3.85.25 allows an attacker to escalate privileges via the /SystemUsers/CreateAppUser components
Published: 2026-07-10
Score: 9.1 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An issue in Invixium IXM WEB version 2.3.85.25 allows attackers to gain higher privileges by abusing the /SystemUsers/CreateAppUser component. This weakness, identified as a lack of proper authorization checks (CWE-269), permits privileged operations that should be restricted to authorized administrators.

Affected Systems

Invixium IXM WEB version 2.3.85.25 is affected. No other vendors or products are listed.

Risk and Exploitability

The CVSS score of 9.1 indicates a high severity risk. The EPSS score is less than 1%, and the vulnerability is not yet listed in the CISA KEV catalog. Based on the description, the likely attack vector involves accessing the web interface and sending requests to the /SystemUsers/CreateAppUser endpoint; the flaw enables privilege escalation without proper validation. Attackers could, therefore, create privileged application users and elevate their own privileges.

Generated by OpenCVE AI on July 29, 2026 at 11:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Invixium IXM WEB to a version that resolves the privilege escalation to required.
  • Implement strict role-based access control and least privilege enforcement to ensure that only authorized users can create application users.
  • Configure the web application to restrict the /SystemUsers/CreateAppUser endpoint to authenticated administrator sessions only.

Generated by OpenCVE AI on July 29, 2026 at 11:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 29 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via /SystemUsers/CreateAppUser in Invixium IXM WEB 2.3.85.25

Sun, 26 Jul 2026 14:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via /SystemUsers/CreateAppUser in Invixium IXM WEB

Sat, 18 Jul 2026 05:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via /SystemUsers/CreateAppUser in Invixium IXM WEB

Thu, 16 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Unrestricted Application User Creation in Invixium IXM WEB

Wed, 15 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Unrestricted Application User Creation in Invixium IXM WEB

Tue, 14 Jul 2026 03:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via /SystemUsers/CreateAppUser in Invixium IXM WEB

Mon, 13 Jul 2026 00:45:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via /SystemUsers/CreateAppUser in Invixium IXM WEB

Sun, 12 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via /SystemUsers/CreateAppUser in Invixium IXM WEB v2.3.85.25

Sat, 11 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via /SystemUsers/CreateAppUser in Invixium IXM WEB v2.3.85.25

Fri, 10 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 17:15:00 +0000

Type Values Removed Values Added
Description An issue in Invixium IXM WEB v.2.3.85.25 allows an attacker to escalate privileges via the /SystemUsers/CreateAppUser components
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-07-10T18:03:27.940Z

Reserved: 2026-06-07T00:00:00.000Z

Link: CVE-2026-51119

cve-icon Vulnrichment

Updated: 2026-07-10T18:03:24.372Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T11:45:03Z

Weaknesses
  • CWE-269

    Improper Privilege Management