Executive brief
KitLogistic is a logistics management application used by businesses to track and manage shipments and warehouse operations. A missing authorization vulnerability allows unauthenticated or low-privileged attackers to access sensitive functionality that should be restricted, potentially exposing business operations, order data, and shipping information to unauthorized parties.
Technical details
The vulnerability is a missing authorization / insufficient access control issue in KitLogistic where sensitive application functionality is not properly constrained by access control lists (ACLs). An attacker can access restricted features without proper authentication or authorization checks. The vulnerability affects KitLogistic versions before 2.2.2. An attacker can leverage improper ACL enforcement to access or modify sensitive logistics data and operations beyond their intended permissions.
Affected products
- TBC Technology Inc. KitLogistic before 2.2.2
Timeline
- 2026-08-31: disclosed
- 2026-08-31: advisory