Executive brief
Magarsus IDM-MFA, a solution used for identity management and multi-factor authentication, contains a vulnerability that allows attackers to bypass security checks. By exploiting this flaw, an unauthorized individual could gain access to protected systems or user accounts without providing the required credentials. This poses a significant risk to data privacy and the overall security of the corporate network.
Technical details
An authentication bypass vulnerability exists in Magarsus IDM-MFA due to improper validation of specified types of input (CWE-1287). The flaw allows a remote attacker to circumvent authentication mechanisms by providing unexpected input types that the application fails to process correctly. According to the CVSS vector, the attack is network-based and requires user interaction, but does not require prior administrative privileges. Successful exploitation allows the attacker to achieve high impact on confidentiality and integrity. The issue affects versions released between 2025.11.27 and 2026.03.10.
Affected products
- Magarsus Consulting Ltd. Co. IDM-MFA 2025.11.27 to 2026.03.10
Timeline
- 2026-03-10: patched: Vulnerability fixed in versions starting from this date.
- 2026-07-22: advisory: CVE published by TR-CERT and NVD.