CVE-2026-6853 PUBLISHED

OTP Bypass in Başbelen Group's Pause+ Mobile App

Assigner: TR-CERT
Reserved: 22.04.2026 Published: 12.06.2026 Updated: 12.06.2026

Improper restriction of excessive authentication attempts vulnerability in Başbelen Group Food Cafe Businesses Industry and Trade Ltd. Co. Pause+ Mobile App allows Authentication Bypass.

This issue affects Pause+ Mobile App: from v1.0.6 before v1.5.

Metrics

CVSS Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS Score: 9.8

Product Status

Vendor Başbelen Group Food Cafe Businesses Industry and Trade Ltd. Co.
Product Pause+ Mobile App
Versions Default: unaffected
  • affected from v1.0.6 to v1.5 (excl.)

Credits

  • Oğuz DAVUTOĞLU finder

References

Problem Types

  • CWE-307 Improper restriction of excessive authentication attempts CWE

Impacts

  • CAPEC-115 Authentication Bypass