Executive brief
Adam Retail Automation Ltd. MobilMen 20T, a retail automation system, contains a security flaw that allows users to bypass authorization controls. By manipulating specific data keys, a low-privileged user can gain unauthorized access to administrative functions or sensitive data. This could lead to a complete takeover of the system, data theft, or disruption of retail operations.
Technical details
The vulnerability is classified as CWE-639 (Authorization Bypass Through User-Controlled Key). It exists in the MobilMen 20T retail automation software from version v3 through 10072026. An authenticated attacker with low privileges can exploit this by manipulating keys or identifiers within requests to access resources or perform actions belonging to higher-privileged users. The attack is network-reachable and does not require user interaction. As of the disclosure date, the vendor has not responded to reports, and no official patch has been confirmed.
Affected products
- Adam Retail Automation Ltd. MobilMen 20T v3 through 10072026
Timeline
- 2026-07-10: advisory: NVD and TR-CERT published the vulnerability details.
- 2026-07-10: disclosed: Public disclosure occurred after the vendor failed to respond to early contact.