Executive brief
EdoWEB is a web application platform used to manage organizational workflows and access control. A flaw in how the application validates authorization keys allows attackers to bypass access controls and reach functionality they should not have permission to access, potentially exposing sensitive features and data.
Technical details
The vulnerability is an authorization bypass caused by improper validation of user-controlled keys in access control checks. An attacker can manipulate authorization parameters to circumvent ACL (Access Control List) enforcement, gaining access to restricted functionality without proper authentication or authorization. No special privileges or user interaction is required; the flaw is exploitable over the network. The vulnerability affects EdoWEB versions before 780-g7, and patches are available in the fixed release.
Affected products
- Netiket Information Technologies EdoWEB before 780-g7
Timeline
- 2026-08-18: disclosed