CVE-2026-17562 PUBLISHED

IDOR in Zirve Security's AdisyonPro

Assigner: TR-CERT
Reserved: 27.07.2026 Published: 27.08.2026 Updated: 27.08.2026

Authorization bypass through User-Controlled key vulnerability in Summit Security Systems AdisyonPro allows Accessing Functionality Not Properly Constrained by ACLs.

This issue affects AdisyonPro: before v5.21.0.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
CVSS Score: 6.5

Product Status

Vendor Summit Security Systems
Product AdisyonPro
Versions Default: unaffected
  • affected from 0 to v5.21.0 (excl.)

Credits

  • Seher KARAKAYA finder
  • Mustafa Anıl YILDIRIM coordinator

References

Problem Types

  • CWE-639 Authorization bypass through User-Controlled key CWE

Impacts

  • CAPEC-1 Accessing Functionality Not Properly Constrained by ACLs