{"id":"CVE-2026-12384","title":"Authorization bypass through User-Controlled key vulnerability in TECHIN2B TECHIN2B Application allows Privilege Abuse.\n\nThis issue affects TECHIN2B Application: from V1.0.7676.13 through 18092026.\nNOTE: The vendor was contacted early ab…","summary":"Authorization bypass through User-Controlled key vulnerability in TECHIN2B TECHIN2B Application allows Privilege Abuse.\n\nThis issue affects TECHIN2B Application: from V1.0.7676.13 through 18092026.\nNOTE: The vendor was contacted early ab…","severity":"high","cvss":8.8,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-639"],"vendor":"TECHIN2B","product":"TECHIN2B Application","affected":["application >= V1.0.7676.13 <= 18092026"],"published":"2026-09-18","updated":"2026-09-18","sourceUpdated":"2026-09-18T20:17:04.707","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-12384","references":[{"url":"https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-1014","label":"iletisim@usom.gov.tr"}],"tags":["nvd","cve.org"],"epss":0.00309,"epssPercentile":0.23912,"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-18T19:15:48.813903Z"},"ingestedAt":"2026-09-18T08:38:04.097Z","slug":"CVE-2026-12384","body":"## Overview\n\nAuthorization bypass through User-Controlled key vulnerability in TECHIN2B TECHIN2B Application allows Privilege Abuse.\n\nThis issue affects TECHIN2B Application: from V1.0.7676.13 through 18092026.\nNOTE: The vendor was contacted early about this disclosure but did not respond in any way.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":48,"depthScoreParts":{"impact":48.4,"likelihood":0.1,"exploitation":0,"ransomware":0},"changes":[]}