Junglewise Threat Intelligence

CVE-2026-3020: Wakyma application web IDOR account takeover

CVE-2026-3020 · Severity: info · CVSS 8.6 · Published 2026-03-16

Executive brief

Wakyma, a management and marketing platform for veterinary centers, contains a security flaw that allows an attacker to modify other users' account information. By exploiting this vulnerability, a malicious actor could change a victim's email address and then use the password reset process to take full control of their account. This could lead to the exposure of sensitive veterinary clinic data, customer records, and unauthorized access to business operations.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability (CWE-639) exists in the Wakyma web application. An authenticated attacker can manipulate user-controlled keys to modify the profile data of other legitimate users. Specifically, an attacker can change a victim's registered email address to one they control. By subsequently validating the new email and utilizing the 'forgot password' functionality, the attacker can achieve full account takeover. The vulnerability was addressed in the production environment via continuous integration updates deployed on February 19, 2026.

Affected products

  • Wakyma Wakyma application web Versions prior to February 19, 2026

Timeline

  • 2026-02-19: patched: Vulnerabilities fixed in production deployment.
  • 2026-03-16: disclosed: Public advisory published by INCIBE.

References