Junglewise Threat Intelligence

CVE-2026-9493: BankPro E-Service Technology Service Center IDOR in query function

CVE-2026-9493 · Severity: medium · CVSS 6.5 · Published 2026-05-29

Executive brief

The Service Center platform by BankPro E-Service Technology contains a security flaw that allows logged-in users to view order details belonging to other customers. By manipulating specific web parameters, an attacker can bypass intended access controls to retrieve sensitive e-commerce transaction information. This could lead to the exposure of private customer data and business order history.

Technical details

An Insecure Direct Object Reference (IDOR) vulnerability (CWE-639) exists in the Service Center application developed by BankPro E-Service Technology. The flaw is located within a specific query function where the application fails to properly validate that the requesting user has permission to access the requested object. An authenticated remote attacker can exploit this by modifying parameters (such as order IDs) in web requests to retrieve sensitive e-commerce (EC) order details belonging to other users. The vulnerability has been patched server-side by the vendor, and no user action is required.

Affected products

  • BankPro E-Service Technology Service Center

Timeline

  • 2026-05-29: disclosed
  • 2026-05-29: advisory
  • 2026-05-29: patched: Patched server-side by the vendor.

References