{"id":"CVE-2026-72600","summary":"Idurar IDURAR ERP CRM - Broken Access Control","details":"A broken access control vulnerability in Idurar IDURAR ERP CRM 4.1.0 allows unauthenticated remote attackers to download invoice PDF files containing customer PII via the /download router. The router is mounted without authentication middleware, making it publicly accessible. An attacker can enumerate MongoDB ObjectIds to download any invoice in the system without credentials.","modified":"2026-08-13T04:02:58.653905729Z","published":"2026-08-11T11:14:30.032Z","database_specific":{"cna_assigner":"TuranSec","cwe_ids":["CWE-284"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72600.json"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/72xxx/CVE-2026-72600.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-72600"},{"type":"PACKAGE","url":"https://github.com/idurar/idurar-erp-crm"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/idurar/idurar-erp-crm","events":[{"introduced":"0"},{"last_affected":"012f39a43bdb899c9337fe76797f25357d473ff4"}],"database_specific":{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"0"},{"last_affected":"4.1.0"}]}}],"versions":["4.1.0","4.0.0-beta.3","4.0.0-beta.2","4.0.0-beta.1","3.1.4","3.1.3","3.1.2","3.1.1","3.1.0","3.0.1","3.0.0","3.0.0-beta.11","3.0.0-beta.10","3.0.0-beta.9","3.0.0-beta.8","3.0.0-beta.7","3.0.0-beta.6","3.0.0-beta.5","3.0.0-beta.4","3.0.0-beta.3","3.0.0-beta.1","3.0.0-beta.2","3.0.0.beta","2.1.0","2.0.1","2.0.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-72600.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V3","score":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N"}]}