Executive brief
PAVO Pay, a financial payment processing platform, contains a security flaw that allows unauthorized access to sensitive information. By manipulating specific identifiers used by the system, an attacker can bypass security checks to view data they are not permitted to see. This could lead to the exposure of customer financial records or transaction details, potentially impacting the organization's reputation and regulatory compliance. The vendor has not yet responded to reports of this issue.
Technical details
A vulnerability classified as CWE-639 (Authorization Bypass Through User-Controlled Key) exists in PAVO Pay through version 09072026. The flaw occurs when the application uses client-supplied input to access records without sufficiently verifying that the requesting user has the necessary permissions for that specific identifier (Insecure Direct Object Reference). A remote, unauthenticated attacker can exploit this by modifying parameters in network requests to access sensitive data belonging to other users. The vulnerability has a CVSS base score of 7.5, reflecting high confidentiality impact. As of the disclosure date, the vendor has not provided a patch or official response.
Affected products
- PAVO Financial Technology Solutions Inc. PAVO Pay up to and including 09072026
Timeline
- 2026-07-09: advisory: Initial disclosure by TR-CERT (Computer Emergency Response Team of the Republic of Turkey)
- 2026-07-09: disclosed: Public disclosure via NVD