Junglewise Threat Intelligence

CVE-2026-12686: Adiss Biloop cross-tenant authorization bypass via company ID manipulation

CVE-2026-12686 · Severity: info · CVSS 9.3 · Published 2026-07-06

Executive brief

Adiss Biloop, a digital portal for professional firms and their clients, contains a security flaw that allows one customer to access another customer's data. By simply changing a company ID number in a web request, an authorized user could view or modify sensitive information belonging to other businesses, including billing details. This represents a significant risk to data privacy and integrity for organizations using the platform.

Technical details

A cross-tenant authorization bypass (CWE-639) exists in Adiss Biloop version 6.1.1. The vulnerability is rooted in the application's failure to validate that a 'company ID' parameter provided in a POST request matches the authenticated user's session context. An attacker with valid credentials for one tenant can manipulate this parameter to access or modify data belonging to other tenants within the same subdomain. This allows for unauthorized access to sensitive customer information, including billing data, and potential unauthorized modification of third-party data. The vendor has released a fix, and users are advised to update to the latest version.

Affected products

  • Adiss Biloop 6.1.1

Timeline

  • 2026-07-06: advisory
  • 2026-07-06: disclosed
  • 2026-07-06: patched

References