Executive brief
Akinsoft e-Mutabakat, a financial reconciliation software, contains a security flaw that fails to limit repeated login attempts. This allows an attacker to potentially bypass authentication through brute-force methods, leading to unauthorized access to sensitive financial data and business records. Such an incident could result in data theft, financial fraud, or disruption of corporate reconciliation processes.
Technical details
The vulnerability is classified as CWE-307 (Improper Restriction of Excessive Authentication Attempts) within the Akinsoft e-Mutabakat application. The root cause is a lack of rate-limiting or account lockout mechanisms on the authentication interface. A remote, unauthenticated attacker can exploit this by launching automated brute-force or credential stuffing attacks over the network. Successful exploitation allows the attacker to bypass authentication and gain unauthorized access to the system. The issue is reported to affect version 2.02.06.
Affected products
- Akinsoft e-Mutabakat 2.02.06
Timeline
- 2025-09-04: disclosed
- 2025-09-04: advisory