Description
URL redirection to untrusted site ('open redirect') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System allows Fake the Source of Data.

This issue affects Access Control System: before Versiyon 2.
Published: 2026-09-10
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Open Redirect
Action: Immediate Patch
AI Analysis

Impact

CWE-601 describes an open redirect flaw that permits an attacker to redirect a victim to an arbitrary untrusted site, enabling phishing, credential theft, or delivery of malicious content without the user’s knowledge. In this case the Access Control System allows redirect URLs to be set without proper validation, so any attacker who can craft a URL to the system can force a legitimate user to a malicious domain.

Affected Systems

Armiya Information Technologies Ltd. Co. offers an Access Control System. Versions prior to Versiyon 2 are affected. No other affected versions or products are listed.

Risk and Exploitability

The CVSS score of 9.3 indicates the flaw is high severity and potentially catastrophic. While the EPSS score is not available, the lack of a KEV listing does not reduce the risk because the vulnerability remains exploitable. The attack likely occurs through a crafted link or form parameter that specifies a redirect destination. Without input validation, an attacker can mount phishing attacks against users of the system.

Generated by OpenCVE AI on September 10, 2026 at 10:23 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the Access Control System to version 2 or later, which removes the vulnerable redirect handling.
  • Implement strict whitelist validation for redirect URLs, rejecting or sanitizing any paths that are not explicitly trusted.
  • Monitor redirect requests for unusual patterns or target domains to detect potential exploitation attempts.

Generated by OpenCVE AI on September 10, 2026 at 10:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sun, 13 Sep 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Armiya Information Technologies Ltd. Co.
Armiya Information Technologies Ltd. Co. access Control System
Vendors & Products Armiya Information Technologies Ltd. Co.
Armiya Information Technologies Ltd. Co. access Control System

Thu, 10 Sep 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Description URL redirection to untrusted site ('open redirect') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System allows Fake the Source of Data. This issue affects Access Control System: before Versiyon 2.
Title Open Redirect in Armiya Information Technologies' Access Control System
Weaknesses CWE-601
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N'}


Subscriptions

Armiya Information Technologies Ltd. Co. Access Control System
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-09-10T15:02:30.971Z

Reserved: 2026-05-11T13:53:49.139Z

Link: CVE-2026-8323

cve-icon Vulnrichment

Updated: 2026-09-10T15:02:25.251Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T09:17:06.250

Modified: 2026-09-10T16:18:12.997

Link: CVE-2026-8323

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-13T20:01:32Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')