Executive brief
Dinosoft ERP, a business management software suite, contains a critical security flaw that allows unauthorized individuals to access sensitive administrative functions. Because the system fails to properly verify user identity or enforce access permissions, an attacker could potentially view or modify business data, disrupt operations, or take full control of the software. The vendor has not yet responded to reports of this vulnerability, and no official patch is currently available.
Technical details
Dinosoft ERP suffers from a combination of Missing Authentication for Critical Function (CWE-306) and Improper Access Control (CWE-284). The vulnerability allows a remote, unauthenticated attacker to bypass Access Control Lists (ACLs) and execute sensitive functionality that should be restricted to authorized administrators. The flaw is exploitable over the network with low complexity and requires no user interaction. Affected versions range from versions prior to 3.0.1 through version 11022026. As of the disclosure date, the vendor has not provided a fix.
Affected products
- Dinosoft Business Solutions Dinosoft ERP From < 3.0.1 through 11022026
Timeline
- 2026-02-11: advisory: Initial disclosure by USOM/TR-CERT
- 2026-02-11: disclosed: NVD publication date