Description
Missing Authorization vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows Collect Data from Common Resource Locations.

This issue affects Access Control System (GKS): before Version 2.
Published: 2026-07-07
Score: 8.2 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A missing authorization check in Armiya Information Technologies Ltd. Co. Access Control System (GKS) lets attackers collect data from common resource locations without proper credentials, effectively bypassing the system’s access controls (CWE-862). The flaw permits unauthorized read access to protected information, potentially exposing sensitive data and enabling further malicious activity within the environment.

Affected Systems

Armiya Information Technologies Ltd. Co. Access Control System (GKS) is vulnerable in all releases prior to version 2; no other vendors or products are listed as affected.

Risk and Exploitability

The CVSS score of 8.2 indicates a high‑severity vulnerability. An EPSS score of less than 1% points to a very low exploitation probability, and the issue is not listed in CISA’s KEV catalog. Based on the description, it is inferred that attackers could send requests directly to the GKS API or administrative interface to exploit the missing authorization checks. Anyone with network access to the GKS services could execute this attack, underscoring the need for protective measures.

Generated by OpenCVE AI on July 26, 2026 at 19:33 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Access Control System (GKS) to version 2 or newer to eliminate the missing authorization check.
  • If an immediate upgrade is not feasible, block external access to the GKS API and related interfaces with firewall rules or network segmentation to restrict interaction to trusted hosts only.
  • Conduct a comprehensive audit of all access control configurations in GKS to verify that proper authorization is enforced before deploying the system in a production environment.

Generated by OpenCVE AI on July 26, 2026 at 19:33 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 10 Jul 2026 10:15:00 +0000

Type Values Removed Values Added
First Time appeared Armiya
Armiya access Control System (gks)
Vendors & Products Armiya
Armiya access Control System (gks)

Tue, 07 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 07 Jul 2026 07:30:00 +0000

Type Values Removed Values Added
Description Missing Authorization vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows Collect Data from Common Resource Locations. This issue affects Access Control System (GKS): before Version 2.
Title Improper Authorization in Armiya Technologies' Access Control System
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:N'}


Subscriptions

Armiya Access Control System (gks)
cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-07-07T13:29:16.531Z

Reserved: 2026-05-12T08:45:41.295Z

Link: CVE-2026-8377

cve-icon Vulnrichment

Updated: 2026-07-07T13:29:13.231Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-26T19:45:03Z

Weaknesses