Junglewise Threat Intelligence

CVE-2025-8886: Usta Information Systems Aybs Interaktif auth bypass and privilege abuse

CVE-2025-8886 · Severity: medium · CVSS 6.7 · Published 2025-10-10

Executive brief

Usta Information Systems Aybs Interaktif is an interactive information system. A security flaw in this software allows unauthorized individuals to bypass authentication and gain elevated privileges. This could lead to the exposure of sensitive data and unauthorized changes to the system, potentially compromising operational integrity and customer privacy.

Technical details

The vulnerability encompasses several authorization-related weaknesses, including Incorrect Permission Assignment for Critical Resource (CWE-732), Missing Authorization (CWE-862), and Incorrect Authorization (CWE-863). These flaws allow an attacker to bypass standard authentication mechanisms and abuse system privileges. The attack vector is classified as local with high complexity, meaning an attacker likely needs some level of access to the environment or specific conditions to be met to successfully exploit the flaw. Successful exploitation results in high impacts to confidentiality and integrity. The issue affects versions of Aybs Interaktif released between 2024 and August 28, 2025.

Affected products

  • Usta Information Systems Inc. Aybs Interaktif 2024 through 28082025

Timeline

  • 2025-10-10: advisory: Initial publication of CVE-2025-8886

References

Related threats