Executive brief
Invixium IXM WEB is a biometric security platform used to manage access control and identity for corporate facilities. A security flaw allows a standard user to bypass security checks and create a new administrator account. This could lead to an unauthorized person gaining full control over the security system, including the ability to manage users and access logs.
Technical details
A privilege escalation vulnerability exists in Invixium IXM WEB v2.3.85.25 due to improper authorization (CWE-269) on the POST /SystemUsers/CreateAppUser endpoint. The application fails to perform server-side validation to ensure that only administrative users can access this specific component. An authenticated attacker with low-level privileges can send a crafted POST request to this endpoint to create a new account with full administrative rights. Successful exploitation grants the attacker total control over the application's administrative functions and user management.
Affected products
- Invixium IXM WEB 2.3.85.25
Timeline
- 2026-04-15: disclosed: Vulnerability reported to vendor
- 2026-07-10: advisory: Public advisory released