Junglewise Threat Intelligence

CVE-2026-10597: ITPison OMICARD EDM IDOR vulnerability allows email disclosure

CVE-2026-10597 · Severity: medium · CVSS 5.3 · Published 2026-06-04

Executive brief

OMICARD EDM, an enterprise direct marketing and email management platform, contains a security flaw that allows unauthorized individuals to access user information. By manipulating specific web parameters, an attacker can retrieve the email addresses of registered users without needing to log in. This could lead to large-scale data harvesting, increasing the risk of targeted phishing attacks or privacy breaches for the organization's customers and staff.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability (CWE-639) exists in ITPison OMICARD EDM versions 5.8 through 6.0.5.8. The flaw is located in a component that handles user-specific data requests where authorization checks are insufficient. An unauthenticated remote attacker can exploit this by sending crafted HTTP requests with modified parameters (such as user IDs) to the server. Successful exploitation allows the attacker to bypass intended access controls and retrieve sensitive information, specifically user email addresses. Users are advised to contact the vendor for a patch.

Affected products

  • ITPison (沛盛資訊) OMICARD EDM 5.8 to 6.0.5.8

Timeline

  • 2026-06-02: advisory: Initial disclosure by TWCERT/CC
  • 2026-06-04: disclosed: NVD publication date

References