Description
This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Published: 2026-06-05
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

HAVELSAN Inc.'s Geographic Tracking System contains an Improper Access Control vulnerability (CWE-284, CWE-862) that allows an attacker to access functionality that should be constrained by access control lists. The vulnerability could lead to unauthorized disclosure of sensitive geographic data or manipulation of tracking information, potentially compromising both confidentiality and integrity of the system. The CVSS score of 9.1 indicates a high severity. The description does not specify whether authentication is required, so the threat is derived from the lack of proper authorization checks; it may be exploitable by anyone who can reach the affected functions, whether through authenticated or unauthenticated channels.

Affected Systems

The vulnerability affects HAVELSAN Inc.'s Geographic Tracking System versions prior to v0.0.2.

Risk and Exploitability

With a CVSS score of 9.1 and no EPSS data available, the risk remains high but the likelihood of exploitation is uncertain. The vulnerability is not currently listed in the CISA KEV catalog, and no public exploits are known. The likely attack vector is network-based, targeting exposed APIs or web interfaces where access control checks are insufficient. An attacker could trigger the vulnerability by interacting with the impacted functions without proper authorization, potentially gaining unauthorized access to the system's data and controls.

Generated by OpenCVE AI on June 5, 2026 at 15:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Geographic Tracking System to version v0.0.2 or later
  • Apply configuration changes to enforce role‑based access control, ensuring only authorized users can invoke the affected functionality
  • Review and tighten ACLs for all exposed endpoints, implementing explicit permission checks

Generated by OpenCVE AI on June 5, 2026 at 15:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References

No reference.

History

Fri, 05 Jun 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
CWE-862
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Fri, 05 Jun 2026 17:30:00 +0000

Type Values Removed Values Added
Description Improper Access Control, Missing Authorization vulnerability in HAVELSAN Inc. Geographic Tracking System allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Geographic Tracking System: before v0.0.2. This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
Title Improper Access Control in in HAVELSAN's Geographic Tracking System

Fri, 05 Jun 2026 14:45:00 +0000

Type Values Removed Values Added
Description Improper Access Control, Missing Authorization vulnerability in HAVELSAN Inc. Geographic Tracking System allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Geographic Tracking System: before v0.0.2.
Title Improper Access Control in in HAVELSAN's Geographic Tracking System
Weaknesses CWE-284
CWE-862
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: REJECTED

Assigner: TR-CERT

Published:

Updated: 2026-06-05T16:38:21.452Z

Reserved: 2026-04-13T12:16:25.846Z

Link: CVE-2026-6209

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Rejected

Published: 2026-06-05T15:16:53.977

Modified: 2026-06-05T18:17:34.577

Link: CVE-2026-6209

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-05T15:30:13Z

Weaknesses

No weakness.