Broken Access Control in Idurar ERP CRM Allows Unauthenticated Access
CVE-2026-72600

7.5HIGH

Key Information:

Vendor

Idurar

Vendor
CVE Published:
11 August 2026

What is CVE-2026-72600?

A significant broken access control flaw found in Idurar ERP CRM version 4.1.0 enables unauthenticated remote attackers to download invoice PDF files containing sensitive customer Personally Identifiable Information (PII). This vulnerability exists due to the lack of authentication middleware on the /download router, rendering it publicly accessible. Attackers can exploit this weakness by enumerating MongoDB ObjectIds, allowing them to download any invoice within the system without needing credentials.

Affected Version(s)

IDURAR ERP CRM 0 <= 4.1.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Bobur Abdugafforov
.