Description
URL redirection to untrusted site ('open redirect') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System allows Fake the Source of Data.

This issue affects Access Control System: before Versiyon 2.
Published: 2026-09-10
Score: 9.3 Critical
EPSS: < 1% Very Low
KEV: No
Impact: Open Redirect
Action: Immediate Patch
AI Analysis

Impact

CWE-601 describes an open redirect flaw that permits an attacker to redirect a victim to an arbitrary untrusted site, enabling phishing, credential theft, or delivery of malicious content without the user’s knowledge. In this case the Access Control System allows redirect URLs to be set without proper validation, so any attacker who can craft a URL to the system can force a legitimate user to a malicious domain.

Affected Systems

Armiya Information Technologies Ltd. Co. offers an Access Control System. Versions prior to Versiyon 2 are affected. No other affected versions or products are listed.

Risk and Exploitability

The CVSS score of 9.3 indicates the flaw is high severity and potentially catastrophic. While the EPSS score is not available, the lack of a KEV listing does not reduce the risk because the vulnerability remains exploitable. The attack likely occurs through a crafted link or form parameter that specifies a redirect destination. Without input validation, an attacker can mount phishing attacks against users of the system.

Generated by OpenCVE AI on September 10, 2026 at 10:23 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the Access Control System to version 2 or later, which removes the vulnerable redirect handling.
  • Implement strict whitelist validation for redirect URLs, rejecting or sanitizing any paths that are not explicitly trusted.
  • Monitor redirect requests for unusual patterns or target domains to detect potential exploitation attempts.

Generated by OpenCVE AI on September 10, 2026 at 10:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 09:00:00 +0000

Type Values Removed Values Added
Description URL redirection to untrusted site ('open redirect') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System allows Fake the Source of Data. This issue affects Access Control System: before Versiyon 2.
Title Open Redirect in Armiya Information Technologies' Access Control System
Weaknesses CWE-601
References
Metrics cvssV3_1

{'score': 9.3, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-09-10T08:49:12.084Z

Reserved: 2026-05-11T13:53:49.139Z

Link: CVE-2026-8323

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-09-10T09:17:06.250

Modified: 2026-09-10T09:17:06.250

Link: CVE-2026-8323

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T10:30:04Z

Weaknesses
  • CWE-601

    URL Redirection to Untrusted Site ('Open Redirect')