Executive brief
Liderahenk, a central management system for corporate IT infrastructure, contains a security flaw where critical functions do not properly verify user identity. This vulnerability could allow an attacker to perform unauthorized actions, potentially leading to the inclusion of malicious code within the system. If exploited, this could compromise the integrity of the management platform and the systems it controls.
Technical details
A Missing Authentication for Critical Function vulnerability (CWE-306) exists in Liderahenk versions 3.0.0 through 3.3.1. The flaw allows for Remote Code Inclusion because certain sensitive operations do not require proper authentication. While the attack vector is network-based, the CVSS score indicates that high privileges and user interaction are required for successful exploitation. An attacker successfully leveraging this flaw could execute unauthorized code or modify system configurations. The issue is addressed in version 3.5.0.
Affected products
- TUBITAK BILGEM Software Technologies Research Institute Liderahenk 3.0.0 to 3.3.1 before 3.5.0
Timeline
- 2026-02-17: disclosed
- 2026-02-17: advisory