Junglewise Threat Intelligence

CVE-2025-15025: Yordam Library Automation System authorization bypass via user-controlled key

CVE-2025-15025 · Severity: high · CVSS 8.8 · Published 2026-05-14

Technologies: Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Automation System. Vendors: Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc..

Executive brief

A security vulnerability has been identified in the Yordam Library Automation System, a platform used to manage library resources and member data. An attacker can bypass security checks by manipulating specific identifiers, potentially gaining unauthorized access to sensitive information or administrative functions. This could lead to the exposure of patron data or unauthorized changes to the library's digital records.

Technical details

The vulnerability is classified as CWE-639 (Authorization Bypass Through User-Controlled Key). It exists in the Yordam Library Automation System between versions 21.6 and 22.1. The flaw allows a remote attacker to bypass authorization mechanisms by manipulating trusted identifiers (such as IDs or keys) within the application's requests. While the attack vector is network-based and requires low complexity, the CVSS metric indicates that user interaction is required. Successful exploitation allows the attacker to view, modify, or delete data they are not authorized to access. The issue is addressed in version 22.1.

Affected products

  • Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Automation System v.21.6 to v.22.1

Timeline

  • 2026-05-14: advisory: NVD published the CVE record based on TR-CERT data.
  • 2026-05-14: disclosed: Vulnerability disclosed by the Computer Emergency Response Team of the Republic of Turkey.

References

Related threats