Authentication Bypass in Hayat Mobile by Hayat Health Facilities Inc.
CVE-2026-90983

8.2HIGH

What is CVE-2026-90983?

A client-side authentication vulnerability exists in the Hayat Mobile application developed by Hayat Health Facilities Inc. This issue allows an attacker to bypass authentication mechanisms, potentially leading to unauthorized access. The vulnerability impacts versions 3.3.0 up to, but not including, 3.4.0, making it critical for users of these versions to apply necessary updates to safeguard their sensitive data.

Affected Version(s)

Hayat Mobile 3.3.0 < 3.4.0

References

CVSS V3.1

Score:
8.2
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Serdar ÇATAL
.