Executive brief
HAVELSAN's Geographic Tracking System, used for monitoring and managing location-based data, contains a critical security flaw. This vulnerability allows unauthorized individuals to bypass security controls by manipulating user-controlled keys or identifiers. An attacker could exploit this to gain unauthorized access to sensitive tracking information or modify data, potentially compromising the integrity of the entire tracking operation.
Technical details
The HAVELSAN Geographic Tracking System is vulnerable to an Insecure Direct Object Reference (IDOR) style authorization bypass (CWE-639). The flaw exists because the application relies on user-controlled keys or identifiers to grant access to resources without performing adequate server-side validation of the requester's permissions. A remote, unauthenticated attacker can exploit this over the network by providing manipulated identifiers to access or modify data belonging to other trusted entities. This issue is resolved in version 0.0.2 and later.
Affected products
- HAVELSAN Inc. Geographic Tracking System before v0.0.2
Timeline
- 2026-06-05: disclosed
- 2026-06-05: advisory