Impact
Teracity Software Technologies Inc. TeraMIS is vulnerable to an IDOR flaw where an attacker can manipulate a user‑controlled key to reference resources they normally cannot access. This breach of authorization can lead to unauthorized privilege abuse, potentially exposing sensitive data and compromising confidentiality and integrity. The weakness maps to CWE‑639 – Broken Object Level Authorization.
Affected Systems
All TeraMIS installations from version V03.26.01.14 through 30.04.2026 are affected. The vulnerability is limited to the Teracity Software Technologies Inc. product line.
Risk and Exploitability
The flaw carries a CVSS score of 8.8, indicating high severity. The EPSS score of less than 1% suggests a very low likelihood of exploitation, and it is not listed in CISA’s KEV catalog. It is inferred that an attacker would need an authenticated user with limited privileges to submit manipulated requests via the web interface, exploiting the lack of proper ownership checks to access resources they do not own.
OpenCVE Enrichment