Junglewise Threat Intelligence

CVE-2025-10912: Saastech TemizlikYolda authorization bypass via user-controlled key

CVE-2025-10912 · Severity: medium · CVSS 5.4 · Published 2026-02-11

Executive brief

TemizlikYolda, a service platform for cleaning and internet services, contains a security flaw that allows users to bypass authorization controls. By manipulating specific data keys or variables, an authenticated user could potentially access or modify information belonging to other users. This could lead to unauthorized data changes or service disruptions, and the vendor has not yet responded to reports of this issue.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability, classified as CWE-639 (Authorization Bypass Through User-Controlled Key), exists in the TemizlikYolda platform. The flaw allows a remote attacker with low-level authentication to manipulate variables or keys within application requests to bypass intended access controls. This can result in unauthorized modification of data or impact service availability. The vulnerability is present in versions through February 11, 2026, and as of the disclosure date, the vendor has not provided a patch or official response.

Affected products

  • Saastech Cleaning and Internet Services Inc. TemizlikYolda through 11022026

Timeline

  • 2026-02-11: advisory: Initial disclosure by TR-CERT/USOM
  • 2026-02-11: disclosed: Public disclosure date

References

Related threats