Executive brief
Wakyma, a management and marketing platform for veterinary centers, contains a security flaw that allows an attacker to modify other users' account information. By exploiting this vulnerability, a malicious actor could change a victim's email address and then use the password reset process to take full control of their account. This could lead to the exposure of sensitive veterinary clinic data, customer records, and unauthorized access to business operations.
Technical details
An Insecure Direct Object Reference (IDOR) vulnerability (CWE-639) exists in the Wakyma web application. An authenticated attacker can manipulate user-controlled keys to modify the profile data of other legitimate users. Specifically, an attacker can change a victim's registered email address to one they control. By subsequently validating the new email and utilizing the 'forgot password' functionality, the attacker can achieve full account takeover. The vulnerability was addressed in the production environment via continuous integration updates deployed on February 19, 2026.
Affected products
- Wakyma Wakyma application web Versions prior to February 19, 2026
Timeline
- 2026-02-19: patched: Vulnerabilities fixed in production deployment.
- 2026-03-16: disclosed: Public advisory published by INCIBE.