Junglewise Threat Intelligence

CVE-2026-2398: Adam Retail Automation Ltd. MobilMen 20T authorization bypass

CVE-2026-2398 · Severity: high · CVSS 8.8 · Published 2026-07-10

Executive brief

Adam Retail Automation Ltd. MobilMen 20T, a retail automation system, contains a security flaw that allows users to bypass authorization controls. By manipulating specific data keys, a low-privileged user can gain unauthorized access to administrative functions or sensitive data. This could lead to a complete takeover of the system, data theft, or disruption of retail operations.

Technical details

The vulnerability is classified as CWE-639 (Authorization Bypass Through User-Controlled Key). It exists in the MobilMen 20T retail automation software from version v3 through 10072026. An authenticated attacker with low privileges can exploit this by manipulating keys or identifiers within requests to access resources or perform actions belonging to higher-privileged users. The attack is network-reachable and does not require user interaction. As of the disclosure date, the vendor has not responded to reports, and no official patch has been confirmed.

Affected products

  • Adam Retail Automation Ltd. MobilMen 20T v3 through 10072026

Timeline

  • 2026-07-10: advisory: NVD and TR-CERT published the vulnerability details.
  • 2026-07-10: disclosed: Public disclosure occurred after the vendor failed to respond to early contact.

References

Related threats