Junglewise Threat Intelligence

CVE-2025-9062: MeCODE Envanty authorization bypass via user-controlled key

CVE-2025-9062 · Severity: high · CVSS 7.3 · Published 2026-02-19

Executive brief

A security flaw in the Envanty platform allows users to bypass authorization checks by manipulating specific data keys or parameters. This could allow an attacker with basic access to the local network to view or modify data belonging to other users. The issue has been addressed in version 1.0.6, though the vendor did not officially respond to the initial disclosure.

Technical details

The vulnerability is classified as CWE-639 (Authorization Bypass Through User-Controlled Key) and involves parameter injection within the Envanty platform. An attacker with low-level privileges and adjacent network access can manipulate input keys to bypass authorization logic. This allows the attacker to access or modify records they are not authorized to manage. The issue affects all versions prior to 1.0.6; testing by the reporter indicates that version 1.0.6 remediates the flaw.

Affected products

  • MeCODE Informatics and Engineering Services Ltd. Envanty before 1.0.6

Timeline

  • 2026-02-19: disclosed: Initial disclosure by TR-CERT (USOM)
  • 2026-02-19: advisory
  • 2026-02-19: patched: Remediated in version 1.0.6 according to reporter testing

References