Security Advisory

CVE-2026-72600

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-08-11 11:14:30
Last updated 2026-08-11 15:04:50
Assigner TuranSec
CVSS score not scored
State PUBLISHED

Description

A broken access control vulnerability in Idurar IDURAR ERP CRM 4.1.0 allows unauthenticated remote attackers to download invoice PDF files containing customer PII via the /download router. The router is mounted without authentication middleware, making it publicly accessible. An attacker can enumerate MongoDB ObjectIds to download any invoice in the system without credentials.