Junglewise Threat Intelligence

CVE-2026-6001: ABIS Technology BAPSİS authorization bypass via user-controlled key

CVE-2026-6001 · Severity: high · CVSS 8.8 · Published 2026-05-12

Executive brief

ABIS Technology BAPSİS, a scientific research project management system, contains a security flaw that allows unauthorized users to bypass access controls. By manipulating specific identifiers in web requests, an attacker could gain access to sensitive data or perform actions on behalf of other users. This could lead to the exposure of confidential research data or unauthorized modification of project records.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability, classified as CWE-639, exists in ABIS Technology BAPSİS versions prior to v.202604152042. The application fails to properly validate that the requesting user has the authority to access or modify a resource identified by a user-controlled key. A remote attacker can exploit this by manipulating identifiers (such as IDs in a URL or POST body) to access data belonging to other users or the system. While the CVSS vector indicates user interaction is required (UI:R), the vulnerability is network-reachable and can result in a full compromise of confidentiality, integrity, and availability. A patch has been released in version 202604152042.

Affected products

  • ABIS Technology Ltd. Co. BAPSİS before v.202604152042

Timeline

  • 2026-05-12: advisory: NVD and TR-CERT published the vulnerability details.
  • 2026-04-15: patched: Vendor released version 202604152042 to address the issue.

References