Incorrect access control in Kaleris YMS v7.2.2.1 allows authenticated attackers with only the shipping/receiving role to view the truck's dashboard resources.
References
| Link | Resource |
|---|---|
| https://github.com/Henkel-CyberVM/CVEs/tree/main/CVE-2026-31150 | Exploit Third Party Advisory |
| https://kaleris.com/solutions/yard-management/ | Product |
Configurations
History
10 Apr 2026, 18:03
| Type | Values Removed | Values Added |
|---|---|---|
| References | () https://github.com/Henkel-CyberVM/CVEs/tree/main/CVE-2026-31150 - Exploit, Third Party Advisory | |
| References | () https://kaleris.com/solutions/yard-management/ - Product | |
| CPE | cpe:2.3:a:kaleris:yard_management_solutions:7.2.2.1:*:*:*:*:*:*:* | |
| First Time |
Kaleris
Kaleris yard Management Solutions |
06 Apr 2026, 16:16
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-639 CWE-284 |
|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 4.3 |
06 Apr 2026, 15:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-06 15:17
Updated : 2026-04-10 18:03
NVD link : CVE-2026-31150
Mitre link : CVE-2026-31150
CVE.ORG link : CVE-2026-31150
JSON object : View
Products Affected
kaleris
- yard_management_solutions
