Adiss · Biloop · CVE-2026-12686
**Name of the Vulnerable Software and Affected Versions**
The product name cannot be determined (affected versions not specified)
**Description**
An authenticated user can perform a cross-tenant authorization bypass by manipulating a company ID parameter in a POST request to the backend. The application fails to properly verify if the requested company ID is associated with the authenticated user's session. This flaw allows unauthorized access to sensitive customer information, such as billing data, and may enable the unauthorized modification of third-party data within the same subdomain environment. The vulnerable parameter is `company ID`.
**Recommendations**
At the moment, there is no information about a newer version that contains a fix for this vulnerability.