Authorization Bypass vulnerability in Creartia's ICMS software could allow an attacker to gain unauthorized access to protected features by manipulating the HTTP redirect headers of the login process, causing the script to continue running and enabling privilege escalation without the need for credentials.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

The vulnerability has been fixed by Creartia Internet Consulting S.L. team. It is recommended to update to the last version.


Workaround

No workaround given by the vendor.

History

Mon, 18 May 2026 11:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 18 May 2026 10:45:00 +0000

Type Values Removed Values Added
Description Authorization Bypass vulnerability in Creartia's ICMS software could allow an attacker to gain unauthorized access to protected features by manipulating the HTTP redirect headers of the login process, causing the script to continue running and enabling privilege escalation without the need for credentials.
Title Authorization Bypass in ICMS Content Management by Creartia Internet Consulting
Weaknesses CWE-288
References
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: INCIBE

Published:

Updated: 2026-05-18T11:09:54.218Z

Reserved: 2026-03-17T11:07:32.587Z

Link: CVE-2026-4320

cve-icon Vulnrichment

Updated: 2026-05-18T11:09:47.972Z

cve-icon NVD

Status : Received

Published: 2026-05-18T11:16:18.283

Modified: 2026-05-18T11:16:18.283

Link: CVE-2026-4320

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-05-18T11:30:24Z

Weaknesses