---
id: CVE-2026-15491
title: >-
  A weakness has been identified in RafyMrX TOKO-ONLINE-ROTI up to
  ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99
summary: >-
  A weakness has been identified in RafyMrX TOKO-ONLINE-ROTI up to
  ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. This affects an unknown part. This
  manipulation causes missing authentication. The attack is possible to be
  carried out remotely. …
severity: high
cvss: 7.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-287
  - CWE-306
published: '2026-07-12'
updated: '2026-07-12'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-15491'
references:
  - url: 'https://vuldb.com/cve/CVE-2026-15491'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/submit/844137'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/377798'
    label: cna@vuldb.com
  - url: 'https://vuldb.com/vuln/377798/cti'
    label: cna@vuldb.com
tags:
  - nvd
ingestedAt: '2026-07-12T10:20:07.171Z'
epss: 0.00654
epssPercentile: 0.49124
---

## Overview

A weakness has been identified in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. This affects an unknown part. This manipulation causes missing authentication. The attack is possible to be carried out remotely. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The vendor was contacted early about this disclosure but did not respond in any way.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
