Junglewise Threat Intelligence

CVE-2026-1816: TEİAŞ Mobile Application brute force vulnerability

CVE-2026-1816 · Severity: medium · CVSS 6.3 · Published 2026-05-21

Executive brief

The mobile application for the Turkiye Electricity Transmission Corporation (TEİAŞ) contains a security flaw that fails to limit the number of failed login attempts. This could allow an attacker to repeatedly guess user passwords until they gain unauthorized access to an account. Such access could lead to the exposure of sensitive utility data or unauthorized actions within the application.

Technical details

The TEİAŞ mobile application is vulnerable to a brute-force attack due to improper restriction of excessive authentication attempts (CWE-307). The application does not implement sufficient rate limiting or account lockout mechanisms on its login interface. A network-based attacker can automate numerous login attempts to guess valid credentials. While the CVSS vector suggests some level of user interaction or existing low-privilege access may be involved in the specific exploit scenario, the primary impact is the potential for unauthorized access to sensitive information. The vulnerability is addressed in versions starting from 1.13.

Affected products

  • Turkiye Electricity Transmission Corporation (TEİAŞ) Mobile Application 1.6.2 to 1.13

Timeline

  • 2026-05-21: disclosed: Initial publication of the CVE record.
  • 2026-05-21: advisory: Advisory released by the Computer Emergency Response Team of the Republic of Turkey (USOM).

References

Related threats