Executive brief
HAVELSAN Liman MYS, a centralized management system used for IT infrastructure, contains a security flaw where access controls are not properly enforced. This allows an authenticated user to access sensitive administrative functions or data that should normally be restricted. An exploit could lead to unauthorized changes to the system configuration or disruption of managed IT services.
Technical details
A missing authorization vulnerability (CWE-862) exists in HAVELSAN Liman MYS prior to version release.Master.1107. The application fails to properly validate user permissions against Access Control Lists (ACLs) for certain functional endpoints. An attacker with low-privileged network access can bypass these checks to execute restricted commands or access sensitive management features. This can result in high impacts to system integrity and availability. The vulnerability is addressed in version release.Master.1107.
Affected products
- HAVELSAN Inc. Liman MYS before release.Master.1107
Timeline
- 2026-07-07: advisory: Published by NVD and TR-CERT