CVE-2026-12384: Broken Access Control in TECHIN2B Application
Authorization bypass through User-Controlled key vulnerability in TECHIN2B TECHIN2B Application allows Privilege Abuse.
This issue affects TECHIN2B Application: from V1.0.7676.13 through 18092026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The reported CVSS vector indicates that an attacker needs low-level privileges (PR:L). Exploitation is network-accessible, requires low attack complexity, and does not require user interaction.
What could a successful attacker do?
The issue is described as an authorization bypass through a user-controlled key that enables privilege abuse. The CVSS metrics indicate potential high impact to confidentiality, integrity, and availability.
Which releases are reported as affected?
The affected range is reported as TECHIN2B Application V1.0.7676.13 through 18092026.
Is a vendor fix or response confirmed?
No vendor response is documented in the provided advisory information. The disclosure notes that the vendor was contacted early but did not respond.