Loading market data...
← Back to CVE feed

CVE-2026-72600

HIGH CVSS 7.5 View on NVD ↗

Description

A broken access control vulnerability in Idurar IDURAR ERP CRM 4.1.0 allows unauthenticated remote attackers to download invoice PDF files containing customer PII via the /download router. The router is mounted without authentication middleware, making it publicly accessible. An attacker can enumerate MongoDB ObjectIds to download any invoice in the system without credentials.

CVSS Vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Published: Aug 11, 2026 12:17 UTC Modified: Aug 11, 2026 16:17 UTC