CVE-2026-3263

A vulnerability was found in go2ismail Asp.Net-Core-Inventory-Order-Management-System up to 9.20250118. Affected by this vulnerability is an unknown functionality of the file /api/Security/ of the component Security API. Performing a manipulation results in improper authorization. Remote exploitation of the attack is possible. The vendor was contacted early about this disclosure but did not respond in any way.
Configurations

Configuration 1 (hide)

cpe:2.3:a:go2ismail:asp.net-core-inventory-order-management-system:*:*:*:*:*:*:*:*

History

03 Mar 2026, 00:41

Type Values Removed Values Added
References () https://github.com/Ghufran2/CVE-Asp.Net-Core-Inventory-Order-Management-System-Advisories/blob/main/Asp.Net-Core-Inventory-Order-Management-System%20IDOR%20to%20Full%20System%20Compromise.md - () https://github.com/Ghufran2/CVE-Asp.Net-Core-Inventory-Order-Management-System-Advisories/blob/main/Asp.Net-Core-Inventory-Order-Management-System%20IDOR%20to%20Full%20System%20Compromise.md - Exploit, Mitigation, Third Party Advisory
References () https://vuldb.com/?ctiid.347986 - () https://vuldb.com/?ctiid.347986 - Permissions Required, VDB Entry
References () https://vuldb.com/?id.347986 - () https://vuldb.com/?id.347986 - Third Party Advisory, VDB Entry
References () https://vuldb.com/?submit.758335 - () https://vuldb.com/?submit.758335 - Third Party Advisory, VDB Entry
First Time Go2ismail asp.net-core-inventory-order-management-system
Go2ismail
CPE cpe:2.3:a:go2ismail:asp.net-core-inventory-order-management-system:*:*:*:*:*:*:*:*

27 Feb 2026, 14:06

Type Values Removed Values Added
Summary
  • (es) Se encontró una vulnerabilidad en go2ismail Asp.Net-Core-Inventory-Order-Management-System hasta la versión 9.20250118. Afectada por esta vulnerabilidad es una funcionalidad desconocida del archivo /api/Security/ del componente Security API. Realizar una manipulación resulta en una autorización indebida. La explotación remota del ataque es posible. Se contactó al proveedor con antelación sobre esta divulgación, pero no respondió de ninguna manera.

26 Feb 2026, 22:20

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-26 22:20

Updated : 2026-03-03 00:41


NVD link : CVE-2026-3263

Mitre link : CVE-2026-3263

CVE.ORG link : CVE-2026-3263


JSON object : View

Products Affected

go2ismail

  • asp.net-core-inventory-order-management-system
CWE
CWE-266

Incorrect Privilege Assignment

CWE-285

Improper Authorization