CVE-2026-19441 PUBLISHED

Unauthenticated API Allows Analytics Data Manipulation in IKAS Technology's Rush

Assigner: TR-CERT
Reserved: 10.08.2026 Published: 21.08.2026 Updated: 21.08.2026

Missing authentication for critical function vulnerability in IKAS Technology Inc. Rush allows Fake the Source of Data.

This issue affects Rush: through 21082026.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
CVSS Score: 5.3

Product Status

Vendor IKAS Technology Inc.
Product Rush
Versions Default: unaffected
  • affected from 0 to 21082026 (incl.)

Credits

  • Basri Akkaya finder

References

Problem Types

  • CWE-306 Missing authentication for critical function CWE

Impacts

  • CAPEC-194 Fake the Source of Data