Junglewise Threat Intelligence

CVE-2026-12384: TECHIN2B Application authorization bypass via user-controlled key

CVE-2026-12384 · Severity: high · CVSS 8.8 · Published 2026-09-18

Executive brief

TECHIN2B Application contains an authorization bypass vulnerability that allows attackers to escalate privileges and abuse the system. The flaw enables attackers with local or network access to circumvent access controls and perform unauthorized actions, potentially compromising user data and system integrity.

Technical details

The vulnerability is a user-controlled key authorization bypass in TECHIN2B Application. The flaw allows attackers to manipulate authentication or authorization checks by controlling security-related keys or tokens. An attacker can exploit this to bypass access controls and gain elevated privileges without proper authorization. The vulnerability affects versions V1.0.7676.13 through 18092026. No patch information is currently available despite vendor contact attempts.

Affected products

  • TECHIN2B TECHIN2B Application V1.0.7676.13 through 18092026

Timeline

  • 2026-09-18: disclosed
  • 2026-09-18: advisory

References