Executive brief
A security flaw has been identified in Turboard FOR-S, a business intelligence and data visualization platform. This vulnerability allows an unauthorized user to gain elevated administrative privileges, potentially leading to full control over the system and its data. Organizations using the affected versions should update immediately to prevent unauthorized access to sensitive business information.
Technical details
Turboard FOR-S is vulnerable to an incorrect authorization flaw (CWE-863) that facilitates privilege escalation. The vulnerability exists in versions released between January 7, 2026, and February 18, 2026. An unauthenticated remote attacker can exploit this issue, though it requires some level of user interaction (UI:R), to gain elevated permissions. Successful exploitation could allow an attacker to perform actions with the privileges of a higher-level user, compromising the confidentiality, integrity, and availability of the platform. A patch was released on February 18, 2026.
Affected products
- E-Kalite Software Hardware Engineering Design and Internet Services Industry and Trade Ltd. Co. Turboard FOR-S From 7.01.2026 before 18.02.2026
Timeline
- 2026-02-18: patched: Vulnerability fixed in updated version
- 2026-05-12: disclosed: CVE published by TR-CERT