Executive brief
The Yaay social media application contains a security flaw that allows unauthorized users to bypass access controls. By manipulating specific identifiers or keys, an attacker could access features or data they are not permitted to see. This could lead to the exposure of private user information or unauthorized changes to account settings, potentially damaging the platform's reputation and user privacy.
Technical details
The Yaay Social Media App is vulnerable to an Insecure Direct Object Reference (IDOR) style authorization bypass (CWE-639). The application fails to properly validate user-controlled keys or identifiers against Access Control Lists (ACLs) before granting access to specific functionality. A remote attacker can exploit this by providing a key belonging to another user or a restricted resource, potentially gaining full access to sensitive data or administrative functions. The vulnerability exists in versions 3.8.0 through 24102025. While the attack vector is network-based, the CVSS vector suggests some level of user interaction may be required for certain exploit scenarios.
Affected products
- APPYAP Technology and Information Inc. Yaay Social Media App 3.8.0 through 24102025
Timeline
- 2026-05-14: advisory: NVD published the vulnerability details.
- 2026-05-14: disclosed: Vulnerability disclosed by the Computer Emergency Response Team of the Republic of Turkey.