CVE-2026-16309: IDOR in Netiket Information Technologies' EdoWEB
Authorization bypass through User-Controlled key vulnerability in Netiket Information Technologies EdoWEB allows Accessing Functionality Not Properly Constrained by ACLs.
This issue affects EdoWEB: before 780-g7.
Affected Software
Event History
Frequently Asked Questions
Which EdoWEB deployments should be considered affected?
EdoWEB versions before 780-g7 are affected. The issue is an authorization bypass involving user-controlled keys and functionality that is not properly constrained by access controls.
What level of access does an attacker need to exploit this issue?
The CVSS vector indicates network reachability, low privileges, no user interaction, and high attack complexity. An attacker would need an existing low-privileged account and must successfully exploit the authorization-control weakness.
What is the available remediation target?
The provided data identifies 780-g7 as the affected-version boundary. Organizations using earlier versions should prioritize moving to 780-g7 or a later available release.