CVE-2026-19424 PUBLISHED

Inventec Appliances|Chiline Cloud - Insecure Direct Object Reference

Assigner: twcert
Reserved: 10.08.2026 Published: 11.08.2026 Updated: 11.08.2026

Chiline Cloud developed by Inventec Appliances has a Insecure Direct Object Reference vulnerability. Unauthenticated remote attackers can modify a specific parameter to read other users' sensitive data.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
CVSS Score: 8.7

Product Status

Vendor Inventec Appliances
Product Chiline Cloud
Versions Default: unaffected
  • affected from 0 to 4.5.9 (incl.)

Solutions

The service provider has resolved the vulnerability at the cloud level; no customer action is required

References

Problem Types

  • CWE-639 Authorization Bypass Through User-Controlled Key CWE

Impacts

  • CAPEC-21 Exploitation of Trusted Identifiers