Impact
The vulnerability in Nomysem is caused by an improper access control mechanism that fails to enforce ACLs on certain application functions. This flaw permits users to invoke privileged operations and access sensitive data that should normally be restricted, thereby exposing confidential information. The weakness is classified as a CWE‑213 type of vulnerability, indicating a failure in proper authorization checks.
Affected Systems
The affected product is Nomysem, developed by NOMYSOFT Informatics Education and Consulting Inc. All releases up through version 08‑07‑2026 are vulnerable. No further version ranges are installation created before or on that date could be susceptible.
Risk and Exploitability
The CVSS score of 6.5 classifies the flaw as moderate. The EPSS score is less than 1%, indicating the likelihood of exploitation is very low. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is not detailed in the description; however, it can be inferred that if an attacker can reach the application’s interface—whether internal or network-facing—where the ACL enforcement is omitted, they may be able to trigger the exposed functionality. The potential impact remains confined to unauthorized access to the protected.
OpenCVE Enrichment