Executive brief
Teracity TeraMIS, a management information system, contains a security flaw that allows users to bypass authorization controls. By manipulating specific keys or identifiers, an authenticated user can gain access to data or functions they are not permitted to use. This could lead to unauthorized data modification, exposure of sensitive information, or full administrative takeover of the system.
Technical details
An authorization bypass vulnerability (CWE-639) exists in Teracity TeraMIS due to insufficient validation of user-controlled keys. An authenticated attacker with low privileges can manipulate input parameters, such as object identifiers or account keys, to access or modify resources belonging to other users or the system itself. The vulnerability is exploitable over the network without user interaction. It affects versions from V03.26.01.14 through those released up to April 30, 2026. Successful exploitation results in a complete compromise of confidentiality, integrity, and availability.
Affected products
- Teracity Software Technologies Inc. TeraMIS V03.26.01.14 through 30.04.2026
Timeline
- 2026-07-10: disclosed: Initial NVD publication
- 2026-07-10: advisory: TR-CERT advisory published