Executive brief
A vulnerability in the Nomysem software allows users to access sensitive information that should be restricted. This occurs because the system's internal security rules are inconsistent, failing to properly block access to certain functions. An attacker with basic user credentials could exploit this to view private data, potentially leading to a breach of confidential information.
Technical details
Nomysem is affected by an information exposure vulnerability (CWE-213) resulting from incompatible security policies. The root cause is a failure to properly constrain functionality via Access Control Lists (ACLs), allowing authenticated users to bypass intended restrictions. An attacker with low-privileged network access can exploit this flaw to access sensitive data or functions they are not authorized to view. As of the disclosure date, the vendor has not responded to reports, and no official patch has been confirmed.
Affected products
- NOMYSOFT Informatics Education and Consulting Inc. Nomysem through 08072026
Timeline
- 2026-07-08: advisory: NVD publication date
- 2026-07-08: disclosed: Initial disclosure by TR-CERT