Junglewise Threat Intelligence

CVE-2026-51119: Invixium IXM WEB privilege escalation in CreateAppUser

CVE-2026-51119 · Severity: info · CVSS 9.1 · Published 2026-07-10

Executive brief

Invixium IXM WEB is a biometric security platform used to manage access control and identity for corporate facilities. A security flaw allows a standard user to bypass security checks and create a new administrator account. This could lead to an unauthorized person gaining full control over the security system, including the ability to manage users and access logs.

Technical details

A privilege escalation vulnerability exists in Invixium IXM WEB v2.3.85.25 due to improper authorization (CWE-269) on the POST /SystemUsers/CreateAppUser endpoint. The application fails to perform server-side validation to ensure that only administrative users can access this specific component. An authenticated attacker with low-level privileges can send a crafted POST request to this endpoint to create a new account with full administrative rights. Successful exploitation grants the attacker total control over the application's administrative functions and user management.

Affected products

  • Invixium IXM WEB 2.3.85.25

Timeline

  • 2026-04-15: disclosed: Vulnerability reported to vendor
  • 2026-07-10: advisory: Public advisory released

References