HIGHVulnerability

CVE-2026-72600

A broken access control vulnerability in Idurar IDURAR ERP CRM 4.1.0 allows unauthenticated remote attackers to download invoice PDF files containing customer PII via the /download router. The router is mounted without authentication middleware, making it publicly accessible. An attacker can enumerate MongoDB ObjectIds to download any invoice in the system without credentials.

Properties

severity
HIGH
score
7.5
epss_score
0.00355
cve_id
CVE-2026-72600
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
published_at
2026-08-11T12:17:43.023
last_modified
2026-09-03T17:51:18.670
epss_percentile
0.28429

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

DESCRIBED_BY (1)

[Source]NVD

HAS_WEAKNESS (1)

[Weakness]Improper Access Control

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-72600 — Ninja Signal Threat Intelligence | Ninja Signal