Junglewise Threat Intelligence

CVE-2026-1019: Gotac Police Statistics Database System missing authentication

CVE-2026-1019 · Severity: info · CVSS 9.8 · Published 2026-01-16

Technologies: Gotac Police Statistics Database System. Vendors: Gotac.

Executive brief

The Gotac Police Statistics Database System contains a critical security flaw where it fails to verify user identity for certain functions. This allows unauthorized individuals to remotely access the system and read, change, or delete sensitive police database records. Such an exploit could lead to significant data breaches, loss of critical law enforcement information, and compromised operational integrity.

Technical details

A missing authentication vulnerability (CWE-306) exists in the Gotac Police Statistics Database System through version 1.0.3. The flaw is located within specific system functionalities that do not require valid credentials before granting access to database operations. An unauthenticated attacker can exploit this over the network to perform CRUD (Create, Read, Update, Delete) operations on the underlying database. Although the CVE was later marked as rejected by the CNA, the original technical disclosure from TWCERT/CC identified the impact as a total compromise of confidentiality, integrity, and availability.

Affected products

  • Gotac Police Statistics Database System up to and including 1.0.3

Timeline

  • 2026-01-15: disclosed: Original disclosure by TWCERT/CC
  • 2026-01-16: advisory: NVD publication date
  • 2026-07-30: other: CVE rejected/withdrawn by CNA

Related threats