Junglewise Threat Intelligence

CVE-2026-11348: HAVELSAN Liman MYS improper cryptographic signature verification

CVE-2026-11348 · Severity: high · CVSS 8.1 · Published 2026-07-07

Technologies: HAVELSAN Liman MYS. Vendors: HAVELSAN.

Executive brief

HAVELSAN Liman MYS, a centralized management system, contains a vulnerability where it fails to properly verify digital signatures. This allows an attacker to impersonate legitimate data sources or provide fraudulent information to the system. If exploited, this could lead to unauthorized data modification, loss of system integrity, and potential full system compromise.

Technical details

A vulnerability classified as CWE-347 (Improper Verification of Cryptographic Signature) exists in HAVELSAN Liman MYS. The system fails to adequately validate the authenticity of cryptographic signatures on incoming data or communications. A remote attacker can exploit this flaw to inject malicious data or commands while masquerading as a trusted source. While the attack complexity is rated as high, a successful exploit grants the attacker the ability to impact the confidentiality, integrity, and availability of the management system. The issue is addressed in version release.Master.1107.

Affected products

  • HAVELSAN Inc. Liman MYS before release.Master.1107

Timeline

  • 2026-07-07: disclosed
  • 2026-07-07: advisory

References

Related threats