Junglewise Threat Intelligence

CVE-2026-7484: ABIS Technology AVESİS access control bypass via web parameter manipulation

CVE-2026-7484 · Severity: medium · CVSS 5.3 · Published 2026-07-24

Executive brief

ABIS Technology AVESİS, a platform used for academic information management, contains a security flaw where it incorrectly trusts data sent from a user's browser. An unauthorized attacker can manipulate specific web parameters to bypass access controls and view information or functions they should not be able to see. This could lead to unauthorized access to sensitive academic data or administrative features.

Technical details

A vulnerability classified as CWE-472 (External Control of Assumed-Immutable Web Parameter) exists in ABIS Technology AVESİS versions prior to 202606251646. The application fails to properly validate or protect parameters that are intended to be immutable, such as those used in Access Control List (ACL) checks. A remote, unauthenticated attacker can manipulate these parameters via the network to gain unauthorized access to restricted functionality or data. The vulnerability is addressed in version 202606251646.

Affected products

  • ABIS Technology Ltd. Co. AVESİS before 202606251646

Timeline

  • 2026-07-24: advisory: CVE published by TR-CERT and NVD
  • 2026-06-25: patched: Version 202606251646 released to address the issue

References