Executive brief
IKAS Technology's Rush product contains a missing authentication vulnerability that allows attackers to spoof the source of data without proper access controls. This could enable unauthorized users to inject or modify data in the system, compromising data integrity and potentially allowing impersonation attacks. The vendor has indicated the product is no longer supported, meaning no patches will be provided.
Technical details
The vulnerability is a missing authentication issue in a critical function within IKAS Technology Rush, which allows attackers to forge or fake the source of data. The flaw stems from insufficient authentication checks on a sensitive operation, permitting unauthenticated or unauthorized actors to manipulate data provenance. The attack vector is network-based with no apparent preconditions beyond network access to the affected function. An attacker can exploit this to perform data spoofing attacks, potentially compromising system integrity and trust. No patch is expected given the vendor's statement that the product is unsupported.
Affected products
- IKAS Technology Inc. Rush through 21082026
Timeline
- 2026-08-21: disclosed