Executive brief
HAVELSAN's Geographic Tracking System, used for monitoring and managing location-based data, contains a critical security flaw. This vulnerability allows unauthorized individuals to access sensitive system functions and data that should be restricted. An attacker could potentially view or modify tracking information, leading to significant privacy breaches or operational disruption.
Technical details
A critical vulnerability exists in HAVELSAN Inc. Geographic Tracking System prior to version 0.0.2 due to improper access control (CWE-284) and missing authorization (CWE-862). The system fails to properly enforce Access Control Lists (ACLs) on certain functionalities. A remote, unauthenticated attacker can exploit this over the network with low complexity to access and execute restricted functions. This can result in high impacts to data confidentiality and integrity, as unauthorized users may view or manipulate tracking data. The issue is addressed in version 0.0.2.
Affected products
- HAVELSAN Inc. Geographic Tracking System before v0.0.2
Timeline
- 2026-06-05: disclosed
- 2026-06-05: advisory