CVE-2026-12859: IDOR in Caz Informatics' Advancity ALMS Cloud
Missing Authorization vulnerability in Caz Informatics Services Trade Inc. Advancity ALMS Cloud allows Accessing Functionality Not Properly Constrained by ACLs.
This issue affects Advancity ALMS Cloud: through 2026-10-08. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Affected Software
Event History
Frequently Asked Questions
What level of access does an attacker need to exploit this issue?
The CVSS vector indicates that an attacker needs low-level privileges (PR:L). Exploitation is network-accessible, requires no user interaction, and has low attack complexity.
What is the expected impact if the issue is exploited?
The reported impact is high confidentiality impact, with no integrity or availability impact indicated. The flaw involves functionality that is not properly constrained by access control lists.
Are affected versions identified?
The advisory identifies Advancity ALMS Cloud as affected through 2026-10-08. No fixed version, patch, or workaround is provided in the available data.