{"id":"CVE-2026-17070","published":"2026-08-04T14:16:30.733","lastModified":"2026-08-04T16:16:21.230","description":"Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained by ACLs.\n\nThis issue affects Liman MYS: from 2.2.3 before 2.3.1.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-862"],"vendors":[],"products":[],"references":[{"url":"https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0741","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"This vulnerability allows unauthorized access to functionality not properly constrained by ACLs, enabling potential data breaches or system compromises.","exploitability":"Exploitation requires access to the affected Liman MYS version and knowledge of the missing authorization checks; it is moderately difficult.","blast_radius":"If exploited, this could lead to significant data loss or system compromise in real-world scenarios affecting HAVELSAN Inc. clients.","remediation":"Upgrade to Liman MYS version 2.3.1 or later to address the missing authorization vulnerability.","tags":["auth-bypass","web","ics"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T06:46:04.162Z"}}