Account Takeover Vulnerability in IDURAR ERP CRM by IDURAR
CVE-2026-81031

8.6HIGH

Key Information:

Vendor

Idurar

Vendor
CVE Published:
26 August 2026

What is CVE-2026-81031?

The IDURAR ERP CRM contains a critical flaw where the password update mechanism allows an authenticated administrator to change the password of any other administrator account without proper verification. This vulnerability arises because the update process uses an identifier from the URL path, which is not authenticated against the requesting user. As a result, an attacker with valid administrator access can exploit this weakness to set a new password for another administrator account, effectively gaining unauthorized access. This issue highlights the importance of validating user permissions against the identifiers being manipulated during critical processes such as password updates.

Affected Version(s)

idurar-erp-crm 0 <= 4.1.1

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

George Chen
.