Junglewise Threat Intelligence

CVE-2026-6209: HAVELSAN Geographic Tracking System improper access control

CVE-2026-6209 · Severity: critical · CVSS 9.1 · Published 2026-06-05

Technologies: HAVELSAN Inc. Geographic Tracking System. Vendors: HAVELSAN.

Executive brief

HAVELSAN's Geographic Tracking System, used for monitoring and managing location-based data, contains a critical security flaw. This vulnerability allows unauthorized individuals to access sensitive system functions and data that should be restricted. An attacker could potentially view or modify tracking information, leading to significant privacy breaches or operational disruption.

Technical details

A critical vulnerability exists in HAVELSAN Inc. Geographic Tracking System prior to version 0.0.2 due to improper access control (CWE-284) and missing authorization (CWE-862). The system fails to properly enforce Access Control Lists (ACLs) on certain functionalities. A remote, unauthenticated attacker can exploit this over the network with low complexity to access and execute restricted functions. This can result in high impacts to data confidentiality and integrity, as unauthorized users may view or manipulate tracking data. The issue is addressed in version 0.0.2.

Affected products

  • HAVELSAN Inc. Geographic Tracking System before v0.0.2

Timeline

  • 2026-06-05: disclosed
  • 2026-06-05: advisory

References

Related threats