Junglewise Threat Intelligence

CVE-2025-10855: Solvera Software Teknoera authorization bypass via user-controlled key

CVE-2025-10855 · Severity: high · CVSS 7.5 · Published 2026-01-22

Executive brief

A security vulnerability has been identified in Teknoera, a software solution by Solvera Software Services. This flaw allows unauthorized individuals to bypass security checks by manipulating specific identifiers or keys within the system. An attacker could exploit this to access sensitive information that should otherwise be protected, potentially leading to data exposure and a breach of confidentiality.

Technical details

The vulnerability is classified as CWE-639 (Authorization Bypass Through User-Controlled Key). It occurs in Solvera Software Services Trade Inc. Teknoera through version 01102025. The flaw allows a remote, unauthenticated attacker to bypass authorization mechanisms by providing or manipulating keys (such as IDs or account numbers) that the application trusts without sufficient validation. According to the CVSS vector, this is a network-based attack with low complexity and no user interaction required, resulting in a high impact on confidentiality. At the time of the advisory, the primary impact is the unauthorized retrieval of sensitive information.

Affected products

  • Solvera Software Services Trade Inc. Teknoera through 01102025

Timeline

  • 2026-01-22: advisory: Initial advisory published by TR-CERT (USOM)

References

Related threats