Access Control Vulnerability in Özgür KARALAR Kargo Takip Plugin
CVE-2026-25365
6.5MEDIUM
What is CVE-2026-25365?
A missing authorization issue in the Kargo Takip plugin by Özgür KARALAR allows attackers to exploit incorrectly configured access control security levels. This vulnerability primarily impacts versions prior to 0.2.4, leading to unauthorized actions within the application. It's crucial for users to update their plugin to mitigate any potential risks associated with this security flaw.
Affected Version(s)
Kargo Takip 0 <= 0.2.4