Executive brief
The mobile application for the Turkiye Electricity Transmission Corporation (TEİAŞ) contains a security flaw where user sessions do not expire properly. This could allow an unauthorized person to take over a legitimate user's active session and access their account information. This risk is particularly relevant for maintaining the privacy of personnel or operational data managed through the mobile platform.
Technical details
The TEİAŞ Mobile Application (versions 1.6.2 to 1.13) suffers from an insufficient session expiration vulnerability (CWE-613). This flaw occurs when the application fails to invalidate session identifiers after a period of inactivity or after a user logs out, or otherwise maintains session tokens longer than necessary. A remote attacker with low privileges could potentially hijack a user's session, especially if combined with user interaction or network-level interception. This allows the attacker to perform actions on behalf of the victim or access sensitive data. The issue is addressed in versions starting from 1.13.
Affected products
- Turkiye Electricity Transmission Corporation (TEİAŞ) Mobile Application 1.6.2 to 1.13
Timeline
- 2026-05-21: disclosed
- 2026-05-21: advisory