Junglewise Threat Intelligence

CVE-2025-9986: Vadi Corporate Information Systems DIGIKENT sensitive information exposure

CVE-2025-9986 · Severity: high · CVSS 8.2 · Published 2026-02-11

Executive brief

Vadi Corporate Information Systems' DIGIKENT software is vulnerable to an information disclosure flaw. This software is typically used for municipal and corporate resource management. An attacker could exploit this to access sensitive system information, potentially leading to unauthorized data extraction and a loss of confidentiality for the organization.

Technical details

A vulnerability classified as CWE-497 (Exposure of Sensitive System Information to an Unauthorized Control Sphere) exists in Vadi Corporate Information Systems DIGIKENT through version 13092025. The flaw allows a remote, unauthenticated attacker to access sensitive system-level information over the network. This exposure can be leveraged for 'excavation,' likely referring to the systematic extraction of internal data or configuration details. The attack requires no user interaction and has a high impact on data confidentiality. Organizations are advised to contact the vendor for patching information.

Affected products

  • Vadi Corporate Information Systems Ltd. Co. DIGIKENT through 13092025

Timeline

  • 2026-02-11: advisory: Initial publication of the vulnerability details.
  • 2026-06-05: other: CVE record updated with additional references.

References