Executive brief
BizimHesap Online Pre-Accounting Software is a platform used by businesses to manage financial records and accounting tasks. A vulnerability in this software allows an authenticated user to consume excessive system resources because the application does not properly limit or throttle certain requests. This could lead to performance degradation or service outages, impacting the company's ability to access financial data and perform accounting operations.
Technical details
The vulnerability is classified as CWE-770 (Allocation of Resources Without Limits or Throttling) within the BizimHesap Online Pre-Accounting Software. An attacker with low-privileged network access can trigger excessive resource allocation, as the system fails to implement proper rate limiting or resource quotas. This can lead to a partial or full denial-of-service (DoS) by exhausting available system memory, CPU, or disk space. The issue is confirmed to affect versions through 17072026. No specific patch version was detailed in the advisory, though users are advised to monitor for updates from the vendor.
Affected products
- BizimHesap Information Systems Industry and Trade Inc. Online Pre-Accounting Software through 17072026
Timeline
- 2026-07-23: advisory: Published by the Computer Emergency Response Team of the Republic of Turkey (USOM)