CVE-2026-9410: Improper Authorization in Sushmi-pal Invoice-System
A vulnerability has been found in Sushmi-pal Invoice-System up to a0a3faa16dee2621b231ae227333f5761607283b. This vulnerability affects unknown code of the file /profile of the component Profile Workflow. Such manipulation of the argument ID leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The vendor was contacted early about this disclosure but did not respond in any way.
AI Analysis
Technical Summary
This vulnerability in Sushmi-pal Invoice-System up to commit a0a3faa16dee2621b231ae227333f5761607283b allows an attacker with low privileges to remotely manipulate the ID argument in the /profile component of the Profile Workflow, resulting in improper authorization. The flaw enables unauthorized access or actions due to insufficient access control checks. The product uses rolling releases, so specific affected or fixed versions are not clearly defined. The vendor was contacted but did not provide any response or fix information. The CVSS 4.0 base score is 5.3, indicating medium severity.
Potential Impact
An attacker with low privileges can remotely exploit this vulnerability to bypass authorization controls in the Profile Workflow component, potentially accessing or modifying data they should not be authorized to. This could lead to unauthorized information disclosure or modification within the Invoice-System. No evidence of active exploitation in the wild has been reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since the vendor has not responded and no official fix is available, users should monitor for updates from the vendor or community. Until a fix is released, consider restricting access to the affected /profile endpoint or implementing additional access control checks at the network or application level to mitigate unauthorized access.
CVE-2026-9410: Improper Authorization in Sushmi-pal Invoice-System
Description
A vulnerability has been found in Sushmi-pal Invoice-System up to a0a3faa16dee2621b231ae227333f5761607283b. This vulnerability affects unknown code of the file /profile of the component Profile Workflow. Such manipulation of the argument ID leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS v4.0
Score 5.3medium
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
This vulnerability in Sushmi-pal Invoice-System up to commit a0a3faa16dee2621b231ae227333f5761607283b allows an attacker with low privileges to remotely manipulate the ID argument in the /profile component of the Profile Workflow, resulting in improper authorization. The flaw enables unauthorized access or actions due to insufficient access control checks. The product uses rolling releases, so specific affected or fixed versions are not clearly defined. The vendor was contacted but did not provide any response or fix information. The CVSS 4.0 base score is 5.3, indicating medium severity.
Potential Impact
An attacker with low privileges can remotely exploit this vulnerability to bypass authorization controls in the Profile Workflow component, potentially accessing or modifying data they should not be authorized to. This could lead to unauthorized information disclosure or modification within the Invoice-System. No evidence of active exploitation in the wild has been reported.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Since the vendor has not responded and no official fix is available, users should monitor for updates from the vendor or community. Until a fix is released, consider restricting access to the affected /profile endpoint or implementing additional access control checks at the network or application level to mitigate unauthorized access.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- VulDB
- Date Reserved
- 2026-05-24T06:33:07.555Z
- Cvss Version
- 4.0
- State
- PUBLISHED
- Remediation Level
- null
Threat ID: 6a13a4eca5ae1af1aa1936b2
Added to database: 05/25/2026, 01:25:00 UTC
Last enriched: 06/01/2026, 20:18:26 UTC
Last updated: 07/31/2026, 19:23:00 UTC
Views: 73
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.