Description
A broken access control vulnerability in Idurar IDURAR ERP CRM 4.1.0 allows unauthenticated remote attackers to download invoice PDF files containing customer PII via the /download router. The router is mounted without authentication middleware, making it publicly accessible. An attacker can enumerate MongoDB ObjectIds to download any invoice in the system without credentials.
Published: 2026-08-11
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A broken access control flaw in Idurar IDURAR ERP CRM 4.1.0 permits unauthenticated attackers to download invoice PDF files that contain customer PII. The /download router is mounted without any authentication middleware, making it publicly reachable, and the application allows attackers to enumerate MongoDB ObjectIds to retrieve any invoice. As a result, private customer data can be disclosed to anyone who can reach the system, leading to a breach of confidentiality and potential regulatory violations.

Affected Systems

The vulnerability affects Idurar’s IDURAR ERP CRM version 4.1.0. No other versions are currently known to be impacted.

Risk and Exploitability

The CVSS score of 7.5 classifies the flaw as high severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog, but the attack vector is clearly remote and requires no authentication. An attacker can simply hit the endpoint, supply an enumerated ObjectId, and obtain a PDF containing PII. Because no additional conditions are needed, the exploitability is straightforward and the potential impact on customer data confidentiality is significant.

Generated by OpenCVE AI on August 11, 2026 at 16:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest vendor patch or upgrade to a version that protects the /download endpoint with proper authentication middleware.
  • Implement strict access control for the /download route so that only authorized users can retrieve invoice PDFs.
  • If an immediate patch is not available, restrict external network access to the /download endpoint using firewall or ACL rules until remediation is applied.

Generated by OpenCVE AI on August 11, 2026 at 16:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

References
History

Thu, 13 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Idurar
Idurar idurar Erp Crm
Vendors & Products Idurar
Idurar idurar Erp Crm

Tue, 11 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 11:30:00 +0000

Type Values Removed Values Added
Description A broken access control vulnerability in Idurar IDURAR ERP CRM 4.1.0 allows unauthenticated remote attackers to download invoice PDF files containing customer PII via the /download router. The router is mounted without authentication middleware, making it publicly accessible. An attacker can enumerate MongoDB ObjectIds to download any invoice in the system without credentials.
Title Idurar IDURAR ERP CRM - Broken Access Control
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Subscriptions

Idurar Idurar Erp Crm
cve-icon MITRE

Status: PUBLISHED

Assigner: TuranSec

Published:

Updated: 2026-08-11T15:04:50.049Z

Reserved: 2026-08-10T10:33:03.257Z

Link: CVE-2026-72600

cve-icon Vulnrichment

Updated: 2026-08-11T15:04:46.063Z

cve-icon NVD

Status : Received

Published: 2026-08-11T12:17:43.023

Modified: 2026-08-11T16:17:36.370

Link: CVE-2026-72600

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T09:54:32Z

Weaknesses