CVE-2025-9062

Authorization Bypass Through User-Controlled Key vulnerability in MeCODE Informatics and Engineering Services Ltd. Envanty allows Parameter Injection. This issue affects Envanty: before 1.0.6.   NOTE: The vendor was contacted early about this disclosure but did not respond in any way. The vulnerability was learned to be remediated through reporter information and testing.
Configurations

No configuration.

History

05 Jun 2026, 12:16

Type Values Removed Values Added
Summary (en) Authorization Bypass Through User-Controlled Key vulnerability in MeCODE Informatics and Engineering Services Ltd. Envanty allows Parameter Injection.This issue affects Envanty: before 1.0.6.   NOTE: The vendor was contacted early about this disclosure but did not respond in any way. The vulnerability was learned to be remediated through reporter information and testing. (en) Authorization Bypass Through User-Controlled Key vulnerability in MeCODE Informatics and Engineering Services Ltd. Envanty allows Parameter Injection. This issue affects Envanty: before 1.0.6.   NOTE: The vendor was contacted early about this disclosure but did not respond in any way. The vulnerability was learned to be remediated through reporter information and testing.
References
  • () https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0076 -

15 Apr 2026, 00:35

Type Values Removed Values Added
Summary
  • (es) Vulnerabilidad de elusión de autorización a través de clave controlada por el usuario en MeCODE Informatics y Engineering Services Ltd. Envanty permite la inyección de parámetros. Este problema afecta a Envanty: antes de la versión 1.0.6. NOTA: Se contactó al proveedor con antelación sobre esta divulgación, pero no respondió de ninguna manera. Se supo que la vulnerabilidad fue remediada a través de información del informante y pruebas.

19 Feb 2026, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-19 11:15

Updated : 2026-06-17 10:08


NVD link : CVE-2025-9062

Mitre link : CVE-2025-9062

CVE.ORG link : CVE-2025-9062


JSON object : View

Products Affected

No product.

CWE
CWE-639

Authorization Bypass Through User-Controlled Key