Broken Access Control in Idurar ERP CRM Allows Unauthenticated Access
CVE-2026-72600
7.5HIGH
What is CVE-2026-72600?
A significant broken access control flaw found in Idurar ERP CRM version 4.1.0 enables unauthenticated remote attackers to download invoice PDF files containing sensitive customer Personally Identifiable Information (PII). This vulnerability exists due to the lack of authentication middleware on the /download router, rendering it publicly accessible. Attackers can exploit this weakness by enumerating MongoDB ObjectIds, allowing them to download any invoice within the system without needing credentials.
Affected Version(s)
IDURAR ERP CRM 0 <= 4.1.0
