Junglewise Threat Intelligence

CVE-2026-72600: Idurar ERP CRM broken access control in invoice download

CVE-2026-72600 · Severity: high · CVSS 7.5 · Published 2026-08-11

Technologies: Idurar ERP CRM.

Executive brief

Idurar ERP CRM is open-source accounting and invoicing software used by businesses to manage finances and customer data. A vulnerability in version 4.1.0 allows anyone on the internet to download invoice PDF files without logging in, potentially exposing customer personal information, payment details, and business records to unauthorized access.

Technical details

The vulnerability is a broken access control flaw in the /download router endpoint, which is exposed without authentication middleware. An attacker can enumerate MongoDB ObjectIds to craft requests and retrieve any invoice PDF from the system without credentials. The attack vector is network-based and requires no authentication or user interaction—an attacker simply needs network access to the application. This allows unauthorized disclosure of sensitive business and customer data stored in invoices.

Affected products

  • Idurar ERP CRM 4.1.0

Timeline

  • 2026-08-11: disclosed

References