Description
Authorization bypass through User-Controlled key vulnerability in Teracity Software Technologies Inc. TeraMIS allows Privilege Abuse.

This issue affects TeraMIS: from V03.26.01.14 through 30.04.2026.
Published: 2026-07-10
Score: 8.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Teracity Software Technologies Inc. TeraMIS is vulnerable to an IDOR flaw where an attacker can manipulate a user‑controlled key to reference resources they normally cannot access. This breach of authorization can lead to unauthorized privilege abuse, potentially exposing sensitive data and compromising confidentiality and integrity. The weakness maps to CWE‑639 – Broken Object Level Authorization.

Affected Systems

All TeraMIS installations from version V03.26.01.14 through 30.04.2026 are affected. The vulnerability is limited to the Teracity Software Technologies Inc. product line.

Risk and Exploitability

The flaw carries a CVSS score of 8.8, indicating high severity. The EPSS score of less than 1% suggests a very low likelihood of exploitation, and it is not listed in CISA’s KEV catalog. It is inferred that an attacker would need an authenticated user with limited privileges to submit manipulated requests via the web interface, exploiting the lack of proper ownership checks to access resources they do not own.

Generated by OpenCVE AI on July 29, 2026 at 10:22 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade TeraMIS to a release newer than 30.04.2026 to eliminate the IDOR flaw
  • Add or strengthen authorization checks on all endpoints that accept user‑controlled keys, ensuring that the resource being accessed belongs to the authenticated user and that access rights are verified
  • Deploy or configure a web application firewall or similar controls to detect and block suspicious IDOR attempts, such as requests that manipulate key parameters without proper authorization

Generated by OpenCVE AI on July 29, 2026 at 10:22 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 13 Jul 2026 15:15:00 +0000

Type Values Removed Values Added
First Time appeared Teracity
Teracity teramis
Vendors & Products Teracity
Teracity teramis

Fri, 10 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 10 Jul 2026 19:00:00 +0000

Type Values Removed Values Added
Description Authorization bypass through User-Controlled key vulnerability in Teracity Software Technologies Inc. TeraMIS allows Privilege Abuse. This issue affects TeraMIS: from V03.26.01.14 through 30.04.2026.
Title IDOR in Teracity's TeraMIS
Weaknesses CWE-639
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Teracity Teramis
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-07-10T19:13:49.677Z

Reserved: 2026-04-13T12:17:13.977Z

Link: CVE-2026-6212

cve-icon Vulnrichment

Updated: 2026-07-10T19:13:44.299Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T10:30:05Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key