Junglewise Threat Intelligence

CVE-2026-6207: HAVELSAN Geographic Tracking System observable response discrepancy

CVE-2026-6207 · Severity: critical · CVSS 9.1 · Published 2026-06-05

Technologies: HAVELSAN Inc. Geographic Tracking System. Vendors: HAVELSAN.

Executive brief

A vulnerability has been identified in the HAVELSAN Geographic Tracking System, a platform used for monitoring and managing location-based data. The flaw allows unauthorized individuals to gain detailed information about the system's internal structure and configuration by observing differences in how the application responds to various requests. This information can be used to facilitate more advanced attacks, potentially leading to significant data exposure or unauthorized system access.

Technical details

The HAVELSAN Geographic Tracking System is vulnerable to an observable response discrepancy (CWE-204). This occurs when the application provides different responses in a way that reveals internal state or configuration details to an unauthenticated remote attacker. By analyzing these discrepancies, an attacker can perform system footprinting to map out the environment. The vulnerability is rated critical with a CVSS score of 9.1, as it can lead to high confidentiality and integrity impacts. The issue is addressed in versions 0.0.2 and later.

Affected products

  • HAVELSAN Inc. Geographic Tracking System before v0.0.2

Timeline

  • 2026-06-05: disclosed
  • 2026-06-05: advisory

References

Related threats