Incorrect Authorization Vulnerability in TÜBİTAK ULAKBİM UlakPDF
CVE-2026-88916

6.8MEDIUM

Key Information:

Status
Vendor
CVE Published:
24 September 2026

What is CVE-2026-88916?

The UlakPDF application developed by TÜBİTAK ULAKBİM has been identified to have an incorrect authorization vulnerability, which enables an attacker to escalate their privileges. This flaw allows unauthorized users to gain access to restricted functionalities, potentially compromising sensitive data and system integrity. It is crucial for users and administrators of UlakPDF to apply necessary security measures and updates to mitigate risks associated with this vulnerability.

Affected Version(s)

UlakPDF 0 <= 09092026

References

CVSS V3.1

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ahmed Emin Aygören
.