CVE-2026-6001: IDOR in Abis Technology's BAPSİS
Published May 12, 2026
·Updated
Authorization bypass through User-Controlled key vulnerability in ABIS Technology Ltd. Co. BAPSİS allows Exploitation of Trusted Identifiers.
This issue affects BAPSİS: before v.202604152042.
Affected Software
1 affected component
Abis Technology BAPSIS<202604152042
Event History
May 12, 2026
CVE Published
via MITRE·09:53 AM
Data Sourced
via MITRE·09:53 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·10:16 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-6001?
CVE-2026-6001 has been classified as a medium severity vulnerability due to its potential for authorization bypass.
2
How do I fix CVE-2026-6001?
To mitigate CVE-2026-6001, upgrade your BAPSİS installation to version 202604152042 or later.
3
What specific issue does CVE-2026-6001 address?
CVE-2026-6001 addresses an IDOR vulnerability that allows for unauthorized access through user-controlled keys.
4
Which versions of BAPSİS are affected by CVE-2026-6001?
All versions of BAPSİS prior to version 202604152042 are affected by CVE-2026-6001.
5
Can CVE-2026-6001 be exploited remotely?
Yes, CVE-2026-6001 can potentially be exploited remotely by an attacker to bypass authorization.