---
id: CVE-2025-8886
title: >-
  Incorrect Permission Assignment for Critical Resource, Exposure of Sensitive
  Information to an Unauthorized Actor, Missing Authorization, Incorrect
  Authorization vulnerability in Usta Information Systems Inc
summary: >-
  Incorrect Permission Assignment for Critical Resource, Exposure of Sensitive
  Information to an Unauthorized Actor, Missing Authorization, Incorrect
  Authorization vulnerability in Usta Information Systems Inc. Aybs Interaktif
  allows Privi…
severity: medium
cvss: 6.7
cvssVector: 'CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-200
  - CWE-732
  - CWE-862
  - CWE-863
published: '2025-10-10'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T23:10:00.237'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-8886'
references:
  - url: 'https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-25-0329'
    label: iletisim@usom.gov.tr
  - url: 'https://www.usom.gov.tr/bildirim/tr-25-0329'
    label: iletisim@usom.gov.tr
tags:
  - nvd
epss: 0.00161
epssPercentile: 0.04629
ingestedAt: '2026-09-30T23:29:32.424Z'
---

## Overview

Incorrect Permission Assignment for Critical Resource, Exposure of Sensitive Information to an Unauthorized Actor, Missing Authorization, Incorrect Authorization vulnerability in Usta Information Systems Inc. Aybs Interaktif allows Privilege Abuse, Authentication Bypass.

This issue affects Aybs Interaktif: from 2024 through 28082025.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
