{"id":"CVE-2026-85209","title":"Missing Authorization vulnerability in AVEZ Electronics Communication Training and Consultancy Trade Inc","summary":"Missing Authorization vulnerability in AVEZ Electronics Communication Training and Consultancy Trade Inc. Learning Management System (LMS) allows Exploiting Incorrectly Configured Access Control Security Levels.\n\nThis issue affects Learn…","severity":"medium","cvss":6.5,"cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N","cwe":["CWE-862"],"vendor":"AVEZ Electronics Communication Training and Consultancy Trade Inc.","product":"Learning Management System (LMS)","affected":["learning_management_system_lms <= 2026-09-18"],"published":"2026-10-02","updated":"2026-10-02","sourceUpdated":"2026-10-02T13:17:59.100","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-85209","references":[{"url":"https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-1242","label":"iletisim@usom.gov.tr"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-10-02T12:17:44.366Z","slug":"CVE-2026-85209","body":"## Overview\n\nMissing Authorization vulnerability in AVEZ Electronics Communication Training and Consultancy Trade Inc. Learning Management System (LMS) allows Exploiting Incorrectly Configured Access Control Security Levels.\n\nThis issue affects Learning Management System (LMS): through 2026-09-18.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":36,"depthScoreParts":{"impact":35.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}