PT-2026-70144 · Unknown · Idurar Erp/Crm

·

CVE-2026-72600

·

Published

2026-08-11

·

Updated

2026-08-11

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Idurar IDURAR ERP CRM version 4.1.0
Description A broken access control issue allows unauthenticated remote attackers to download invoice PDF files containing customer personally identifiable information (PII). This occurs because the '/download' router is mounted without authentication middleware, leaving it publicly accessible. An attacker can enumerate MongoDB ObjectIds to retrieve any invoice stored in the system without providing credentials.
Recommendations Update Idurar IDURAR ERP CRM version 4.1.0 to a version that implements proper authentication middleware for the '/download' router.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-72600

Affected Products

Idurar Erp/Crm