Junglewise Threat Intelligence

CVE-2026-80444: Abis Technology AVESİS open redirect

CVE-2026-80444 · Severity: medium · CVSS 5.4 · Published 2026-09-23

Executive brief

AVESİS is a web-based system used for data management. An open redirect vulnerability allows an attacker to craft malicious links that redirect users to untrusted websites, potentially leading to phishing attacks or malware distribution. A user clicking a redirected link may be deceived into entering credentials or downloading malicious content.

Technical details

The vulnerability is an open redirect flaw in URL handling that allows input data manipulation to control redirect destinations. An attacker can supply a malicious URL parameter to redirect users to arbitrary external sites without authentication required. The affected versions are 202608201331 through 202608240351, with patches available in later builds.

Affected products

  • Abis Technology AVESİS 202608201331 to 202608240351

Timeline

  • 2026-09-23: disclosed

References