Executive brief
A security flaw has been identified in the MIA Technology Pizzy Library, a software component used for application development. The vulnerability allows users with low-level access to bypass security restrictions and perform actions or view data they are not authorized to see. This could lead to the exposure of sensitive information or unauthorized changes to application settings.
Technical details
The Pizzy Library by MIA Technology Inc. suffers from improper access control (CWE-284) and missing authorization (CWE-862). The vulnerability exists in versions 1.0.0.26250 through 1.3.9.26249. An authenticated attacker with low privileges can exploit incorrectly configured security levels over the network without user interaction. This allows the attacker to bypass intended authorization checks, potentially leading to high confidentiality impact and low integrity impact. Users should update to version 1.3.9.26250 or later to remediate the issue.
Affected products
- MIA Technology Inc. Pizzy Library from 1.0.0.26250 before 1.3.9.26250
Timeline
- 2026-06-15: advisory: Initial publication of CVE-2026-5230
- 2026-06-15: disclosed: Advisory released by TR-CERT (Computer Emergency Response Team of the Republic of Turkey)