Executive brief
AdisyonPro is a security management system used by organizations to control access to sensitive functionality and data. An authorization bypass vulnerability allows attackers to bypass access control lists (ACLs) through user-controlled keys, potentially granting unauthorized access to restricted features and data that should be protected by role-based permissions.
Technical details
The vulnerability is an authorization bypass stemming from improper enforcement of access control lists (ACLs) due to user-controllable key parameters. An unauthenticated or low-privileged attacker can exploit this flaw by manipulating key values to access functionality that should be restricted by ACL policies. The attack requires network access to the AdisyonPro system. A successful exploit allows the attacker to access features and data that are not properly constrained by the existing ACL mechanisms.
Affected products
- Summit Security Systems AdisyonPro before v5.21.0
Timeline
- 2026-08-27: disclosed