Authentication Bypass Vulnerability in Bahçelievler Municipality BiHayat App
CVE-2026-6223

9.4CRITICAL

Key Information:

Vendor
CVE Published:
7 September 2026

What is CVE-2026-6223?

A vulnerability exists in the BiHayat App developed by Bahçelievler Municipality, where the application fails to adequately restrict excessive authentication attempts. This flaw enables unauthorized users to bypass authentication safeguards, potentially leading to unauthorized access to sensitive user data. The affected versions include BiHayat App from 2.1.7 through 07092026. The vendor has been notified regarding this issue but has not provided any response.

Affected Version(s)

BiHayat App 2.1.7 <= 07092026

References

CVSS V3.1

Score:
9.4
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Onur BİLİCİ
Ferit Özner
.