Executive brief
ArgusTech BILGER is susceptible to an authorization bypass vulnerability. An authenticated user can manipulate specific identifiers to access data or resources belonging to other users. This could lead to the unauthorized exposure of sensitive information within the system.
Technical details
An authorization bypass vulnerability (CWE-639) exists in ArgusTech BILGER versions prior to 2.4.6. The flaw is rooted in the application's reliance on user-controlled keys or identifiers to perform authorization checks. An attacker with low-level user privileges can manipulate these trusted identifiers in network requests to access records or functionality they are not authorized to view. This is a classic Insecure Direct Object Reference (IDOR) style vulnerability. The issue is resolved in version 2.4.6.
Affected products
- ArgusTech BILGER before 2.4.6
Timeline
- 2025-09-16: advisory: Initial disclosure by TR-CERT (USOM)
- 2025-09-16: disclosed