CVE-2026-19616: Information Disclosure in TBC Technology's KitLogistic
Published Aug 31, 2026
·Updated
Missing Authorization vulnerability in TBC Technology Inc. KitLogistic allows Accessing Functionality Not Properly Constrained by ACLs.
This issue affects KitLogistic: before v2.2.2.
Affected Software
1 affected component
KitLogistic<2.2.2
Event History
Aug 31, 2026
CVE Published
via MITRE·01:48 PM
Data Sourced
via MITRE·01:48 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Which KitLogistic versions are affected?
KitLogistic versions before 2.2.2 are affected. The provided information does not state whether version 2.2.2 or later contains a fix.
2
Can this be exploited remotely without credentials or user interaction?
Yes. The CVSS vector indicates network-based exploitation with low attack complexity, no privileges required, and no user interaction required.
3
What is the expected impact of successful exploitation?
Successful exploitation can result in high confidentiality impact, meaning unauthorized parties may be able to access sensitive information. No integrity or availability impact is indicated by the provided CVSS vector.