Executive brief
TemizlikYolda, a service platform for cleaning and internet services, contains a security flaw that allows users to bypass authorization controls. By manipulating specific data keys or variables, an authenticated user could potentially access or modify information belonging to other users. This could lead to unauthorized data changes or service disruptions, and the vendor has not yet responded to reports of this issue.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability, classified as CWE-639 (Authorization Bypass Through User-Controlled Key), exists in the TemizlikYolda platform. The flaw allows a remote attacker with low-level authentication to manipulate variables or keys within application requests to bypass intended access controls. This can result in unauthorized modification of data or impact service availability. The vulnerability is present in versions through February 11, 2026, and as of the disclosure date, the vendor has not provided a patch or official response.
Affected products
- Saastech Cleaning and Internet Services Inc. TemizlikYolda through 11022026
Timeline
- 2026-02-11: advisory: Initial disclosure by TR-CERT/USOM
- 2026-02-11: disclosed: Public disclosure date