CVE-2026-71809: Siam Ordering (siam-server) vulnerability
Published Sep 9, 2026
·Updated
Authentication Bypass via Hardcoded Master Verification Code vulnerability in Siam Ordering (siam-server) 1.0.0 allows remote unauthenticated attackers to log in as any user, merchant, or administrator.
Affected Software
1 affected component
Siam Ordering (siam-server)=1.0.0
Event History
Sep 9, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Frequently Asked Questions
1
Who can exploit this issue?
A remote unauthenticated attacker can exploit it. The issue permits login as any user, merchant, or administrator.
2
What level of access can an attacker obtain?
An attacker can authenticate as any account type identified in the advisory, including administrator accounts. This can provide access equivalent to the impersonated account.