Executive brief
A security flaw has been identified in the Related Marketing Cloud (RMC) platform, a tool used for digital marketing and customer engagement. This vulnerability allows unauthorized individuals to bypass security checks by spoofing their identity, which can lead to automated brute-force attacks on user accounts. If exploited, this could result in unauthorized access to marketing data and customer information.
Technical details
An authentication bypass vulnerability (CWE-290) exists in the Related Marketing Cloud (RMC) platform through version 12052026. The flaw stems from improper verification of identity, allowing an attacker to spoof authentication credentials. This weakness facilitates brute-force attacks against the system. The attack can be carried out over the network without prior authentication or user interaction, potentially allowing an attacker to gain unauthorized access to the platform with limited impact on data integrity and confidentiality.
Affected products
- Hedef Media Promotion Interactive Media Marketing Inc. Related Marketing Cloud (RMC) through 12052026
Timeline
- 2026-06-12: disclosed: Initial publication of the CVE record.
- 2026-06-12: advisory: Advisory released by the Computer Emergency Response Team of the Republic of Turkey (TR-CERT).