Authorization Bypass Vulnerability in EdoWEB by Netiket Information Technologies
CVE-2026-16309

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
18 August 2026

What is CVE-2026-16309?

A critical vulnerability exists in the EdoWEB application developed by Netiket Information Technologies, which allows an attacker to bypass authorization controls by exploiting a user-controlled key. This flaw enables access to functionalities that are not adequately restricted by Access Control Lists (ACLs), potentially leading to unauthorized actions within the application. It is crucial for users of EdoWEB prior to version 780-g7 to assess their security posture and apply necessary patches to mitigate risks associated with this vulnerability.

Affected Version(s)

EdoWEB 0 < 780-g7

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

AHMED RESÜL MERİÇ
FATİH AKTÜRK
.