Junglewise Threat Intelligence

CVE-2025-9342: Anadolu Hayat Emeklilik AHE Mobile authorization bypass via user-controlled key

CVE-2025-9342 · Severity: medium · CVSS 6.5 · Published 2025-09-23

Executive brief

Anadolu Hayat Emeklilik's AHE Mobile application, used for managing private pension and life insurance accounts, contains a security flaw that allows users to bypass authorization. By manipulating specific identifiers or keys within the app, an authenticated user could potentially access information belonging to other customers. This could lead to the unauthorized exposure of sensitive personal and financial data.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability, classified as CWE-639 (Authorization Bypass Through User-Controlled Key), exists in the AHE Mobile application. The flaw resides in how the application validates user-provided keys when requesting resources. An authenticated attacker can modify these keys in network requests to access data or perform actions associated with other user accounts. The vulnerability affects versions 1.9.7 through 1.9.8 and was addressed in version 1.9.9. Exploitation requires network connectivity and valid low-privileged user credentials.

Affected products

  • Anadolu Hayat Emeklilik Inc. AHE Mobile from 1.9.7 before 1.9.9

Timeline

  • 2025-09-23: disclosed
  • 2025-09-23: advisory

References