Description
Insertion of sensitive information into sent data vulnerability in Proliz Software Ltd. Co. Proliz's OBS allows Accessing Functionality Not Properly Constrained by ACLs.

This issue affects Proliz's OBS: before v3.6.0.
Published: 2026-07-17
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw stems from inserting sensitive information into outbound data streams and from insufficient enforcement of access control lists. An attacker can embed confidential data into responses transmitted by Proliz's OBS and can access privileged functions that should be protected, resulting in a direct breach of confidentiality and the potential bypass of authorization controls.

Affected Systems

Proliz Software Ltd. Co. Proliz's OBS versions older than 3.6.0 are affected.

Risk and Exploitability

The CVSS score of 7.5 classifies the vulnerability as high severity, while the EPSS score of less than 1% indicates a low probability of exploitation at present. Based on the description, it is inferred that an attacker can trigger the flaw by sending crafted requests over the network, implying a remote attack vector that does not require user interaction. The vulnerability is not listed in CISA’s KEV catalog, but its combination of high impact and potential remote reach warrants timely mitigation.

Generated by OpenCVE AI on July 31, 2026 at 00:28 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Proliz's OBS to version 3.6.0 or later, which removes the data‑exposure flaw.
  • Reconfigure access control lists to ensure that privileged functions are only accessible to authorized users.
  • Implement input validation and sanitization to strip sensitive data from outbound payloads before transmission.

Generated by OpenCVE AI on July 31, 2026 at 00:28 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Proliz Software
Proliz Software obs
Vendors & Products Proliz Software
Proliz Software obs

Fri, 17 Jul 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 17 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}

cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Fri, 17 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Description Insertion of sensitive information into sent data vulnerability in Proliz Software Ltd. Co. Proliz's OBS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Proliz's OBS: before v3.6.0.
Title Sensitive Data Exposure in Proliz's OBS
Weaknesses CWE-201
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Proliz Software Obs
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-07-17T14:52:33.952Z

Reserved: 2026-04-27T13:09:39.937Z

Link: CVE-2026-7189

cve-icon Vulnrichment

Updated: 2026-07-17T14:52:27.032Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T00:30:18Z

Weaknesses
  • CWE-201

    Insertion of Sensitive Information Into Sent Data