Description
Exposure of sensitive information due to incompatible policies vulnerability in NOMYSOFT Informatics Education and Consulting Inc. Nomysem allows Accessing Functionality Not Properly Constrained by ACLs.

This issue affects Nomysem: through 08072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Published: 2026-07-08
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in Nomysem is caused by an improper access control mechanism that fails to enforce ACLs on certain application functions. This flaw permits users to invoke privileged operations and access sensitive data that should normally be restricted, thereby exposing confidential information. The weakness is classified as a CWE‑213 type of vulnerability, indicating a failure in proper authorization checks.

Affected Systems

The affected product is Nomysem, developed by NOMYSOFT Informatics Education and Consulting Inc. All releases up through version 08‑07‑2026 are vulnerable. No further version ranges are installation created before or on that date could be susceptible.

Risk and Exploitability

The CVSS score of 6.5 classifies the flaw as moderate. The EPSS score is less than 1%, indicating the likelihood of exploitation is very low. The vulnerability is not listed in CISA’s KEV catalog. The attack vector is not detailed in the description; however, it can be inferred that if an attacker can reach the application’s interface—whether internal or network-facing—where the ACL enforcement is omitted, they may be able to trigger the exposed functionality. The potential impact remains confined to unauthorized access to the protected.

Generated by OpenCVE AI on July 29, 2026 at 14:31 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor’s patch or a newer version of Nomysem when it is released
  • Review the application’s access controls to ensure that all sensitive functions are correctly constrained by ACLs
  • Limit the network exposure of Nomysem by isolating it inside a secure segment and restricting inbound traffic
  • Monitor application logs for anomalous requests that may indicate attempts to bypass ACLs
  • If a patch is not immediately available, enforce strict role‑based permissions and user‑account controls to mitigate the exposure

Generated by OpenCVE AI on July 29, 2026 at 14:31 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Nomysoft
Nomysoft nomysem
Vendors & Products Nomysoft
Nomysoft nomysem

Wed, 08 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 08 Jul 2026 09:15:00 +0000

Type Values Removed Values Added
Description Exposure of sensitive information due to incompatible policies vulnerability in NOMYSOFT Informatics Education and Consulting Inc. Nomysem allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Nomysem: through 08072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Title Improper Access Control in Nomysoft Informatics' Nomysem
Weaknesses CWE-213
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Nomysoft Nomysem
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-07-08T12:09:27.160Z

Reserved: 2026-04-14T14:24:35.901Z

Link: CVE-2026-6280

cve-icon Vulnrichment

Updated: 2026-07-08T12:09:22.357Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-29T14:45:02Z

Weaknesses
  • CWE-213

    Exposure of Sensitive Information Due to Incompatible Policies