Junglewise Threat Intelligence

CVE-2025-12008: APPYAP Yaay Social Media App authorization bypass via user-controlled key

CVE-2025-12008 · Severity: high · CVSS 8.8 · Published 2026-05-14

Executive brief

The Yaay social media application contains a security flaw that allows unauthorized users to bypass access controls. By manipulating specific identifiers or keys, an attacker could access features or data they are not permitted to see. This could lead to the exposure of private user information or unauthorized changes to account settings, potentially damaging the platform's reputation and user privacy.

Technical details

The Yaay Social Media App is vulnerable to an Insecure Direct Object Reference (IDOR) style authorization bypass (CWE-639). The application fails to properly validate user-controlled keys or identifiers against Access Control Lists (ACLs) before granting access to specific functionality. A remote attacker can exploit this by providing a key belonging to another user or a restricted resource, potentially gaining full access to sensitive data or administrative functions. The vulnerability exists in versions 3.8.0 through 24102025. While the attack vector is network-based, the CVSS vector suggests some level of user interaction may be required for certain exploit scenarios.

Affected products

  • APPYAP Technology and Information Inc. Yaay Social Media App 3.8.0 through 24102025

Timeline

  • 2026-05-14: advisory: NVD published the vulnerability details.
  • 2026-05-14: disclosed: Vulnerability disclosed by the Computer Emergency Response Team of the Republic of Turkey.

References