Description
External control of Assumed-Immutable web parameter vulnerability in ABIS Technology Ltd. Co. AVESİS allows Accessing Functionality Not Properly Constrained by ACLs.

This issue affects AVESİS: before 202606251646.
Published: 2026-07-24
Score: 5.3 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in AVESİS is an external control of an assumed‑immutable web parameter (CWE‑472). The likely attack vector is manipulation of the web parameters. Because the system trusts that certain query or form parameters will not be altered by a client, an attacker can manipulate those values to reach functionality that should be secured behind access control lists. In practice this means that an unauthorized user could invoke protected actions or access data that they are not permitted to view, which could be used for privilege escalation or data exposure. The CVSS score of 5.3 indicates a moderate risk, and the knowledge of the specific parameter and ACL details is not disclosed.

Affected Systems

ABIS Technology Ltd. Co.'s AVESİS product prior to the release dated 202606251646 is affected. Any deployment of the software older than that build, regardless of configuration, is susceptible to the flaw because the version check was introduced only in that release to enforce proper parameter immutability.

Risk and Exploitability

The exploitation probability is very low, as the EPSS score is below 1%, and the vulnerability is not included in the CISA KEV catalog, implying no publicly documented exploitation. Based on the description, it is inferred that the attacker must successfully identify the vulnerable parameter to craft the request. Attackers would need to identify the specific web parameter that is incorrectly considered immutable and submit crafted requests to bypass ACL checks, which requires a basic level of per‑application knowledge but no special privileges. Given the moderate CVSS score, the impact of a successful attack remains significant, but the low likelihood and lack of active exploitation reduce the overall threat posture.

Generated by OpenCVE AI on August 3, 2026 at 20:19 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade AVESİS to version 202606251646 or later, which addresses the parameter‑control flaw.
  • Enforce strict input validation so that any web parameter marked as immutable cannot be altered by external requests.
  • Strengthen ACL enforcement by reviewing and tightening permissions for all exposed functionalities.
  • Implement application logging and monitoring to detect anomalous manipulation of parameter values that could indicate exploitation attempts.

Generated by OpenCVE AI on August 3, 2026 at 20:19 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Abis Technology
Abis Technology avesis
Vendors & Products Abis Technology
Abis Technology avesis

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Description External control of Assumed-Immutable web parameter vulnerability in ABIS Technology Ltd. Co. AVESİS allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects AVESİS: before 202606251646.
Title Improper Access Control in Abis Technology's AVESİS
Weaknesses CWE-472
References
Metrics cvssV3_1

{'score': 5.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Subscriptions

Abis Technology Avesis
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-07-24T13:46:53.759Z

Reserved: 2026-04-30T07:07:30.821Z

Link: CVE-2026-7484

cve-icon Vulnrichment

Updated: 2026-07-24T13:46:50.745Z

cve-icon NVD

Status : Deferred

Published: 2026-07-24T13:18:30.867

Modified: 2026-07-24T20:47:58.773

Link: CVE-2026-7484

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T20:30:04Z

Weaknesses
  • CWE-472

    External Control of Assumed-Immutable Web Parameter