Junglewise Threat Intelligence

CVE-2026-8309: Armiya Access Control System (GKS) Reflected XSS

CVE-2026-8309 · Severity: medium · CVSS 5.4 · Published 2026-07-07

Technologies: Armiya Information Technologies Ltd. Co. Access Control System (GKS). Vendors: Armiya Information Technologies Ltd. Co..

Executive brief

A security vulnerability exists in the Armiya Access Control System (GKS), which is used to manage physical or digital entry permissions. An attacker could use this flaw to execute malicious scripts in the web browser of a legitimate user. This could lead to unauthorized access to user sessions, theft of sensitive information, or the performance of unintended actions on behalf of the user.

Technical details

A reflected cross-site scripting (XSS) vulnerability exists in Armiya Information Technologies Ltd. Co. Access Control System (GKS) versions prior to Version 2. The flaw stems from the improper neutralization of user-supplied input during web page generation (CWE-79). An attacker with low-level privileges can exploit this by tricking a victim into interacting with a specially crafted link, allowing the execution of arbitrary JavaScript in the context of the victim's browser session. This can result in session hijacking or unauthorized data modification. The issue is addressed in Version 2.

Affected products

  • Armiya Information Technologies Ltd. Co. Access Control System (GKS) before Version 2

Timeline

  • 2026-07-07: advisory: Published by NVD and TR-CERT

References

Related threats