External Control Vulnerability in AVESİS by ABIS Technology Ltd.
CVE-2026-7484

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
24 July 2026

What is CVE-2026-7484?

A vulnerability in ABIS Technology Ltd.'s AVESİS software permits unauthorized access by exploiting an external control of an assumed-immutable web parameter. This flaw arises due to the Access Control Lists (ACLs) not properly constraining access to certain functionalities, potentially allowing attackers to perform unauthorized actions. Users of AVESİS versions prior to 202606251646 should take immediate steps to mitigate this security risk.

Affected Version(s)

AVESİS 0 < 202606251646

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Akıner KISA
.