CVE-2026-6217 PUBLISHED

Information Disclosure in Pik Online Software's Portal

Assigner: TR-CERT
Reserved: 13.04.2026 Published: 04.09.2026 Updated: 04.09.2026

Use of a One-Way hash without a salt vulnerability in Pik Online Software Solutions Inc. Pik Online Portal allows Cryptanalysis.

This issue affects Pik Online Portal: through 3.5.1.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:L/A:N
CVSS Score: 6.3

Product Status

Vendor Pik Online Software Solutions Inc.
Product Pik Online Portal
Versions Default: unaffected
  • affected from 0 to 3.5.1 (incl.)

Credits

  • Enes Can ADİL finder

References

Problem Types

  • CWE-759 Use of a One-Way hash without a salt CWE

Impacts

  • CAPEC-97 Cryptanalysis