Junglewise Threat Intelligence

CVE-2026-8377: Armiya Information Technologies Access Control System missing authorization

CVE-2026-8377 · Severity: high · CVSS 8.2 · Published 2026-07-07

Technologies: Armiya Information Technologies Ltd. Co. Access Control System (GKS). Vendors: Armiya Information Technologies Ltd. Co..

Executive brief

Armiya Information Technologies' Access Control System (GKS), which is used to manage physical security and entry points, contains a security flaw that allows unauthorized access to sensitive data. An attacker can remotely collect information from the system's internal storage locations without needing a username or password. This could lead to the exposure of personnel records, access logs, or other sensitive operational data, potentially compromising the physical security of the facility.

Technical details

A missing authorization vulnerability (CWE-862) exists in the Armiya Information Technologies Access Control System (GKS) prior to Version 2. The flaw allows an unauthenticated attacker to access and collect data from common resource locations via the network. With a CVSS score of 8.2, the vulnerability is characterized by a low attack complexity and requires no user interaction or privileges. Successful exploitation results in high confidentiality impact, allowing the retrieval of sensitive system or user data. Users are advised to upgrade to Version 2 or later to remediate this issue.

Affected products

  • Armiya Information Technologies Ltd. Co. Access Control System (GKS) before Version 2

Timeline

  • 2026-07-07: advisory
  • 2026-07-07: disclosed

References

Related threats