{"id":"CVE-2026-18650","published":"2026-08-04T15:16:31.410","lastModified":"2026-08-04T17:16:46.880","description":"Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Privilege Escalation.\n\nThis issue affects Liman MYS: from 2.2.3 before 2.3.1.","cvssScore":8.8,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","cwes":["CWE-862"],"vendors":[],"products":[],"references":[{"url":"https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0741","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw is a missing authorization vulnerability that allows privilege escalation in HAVELSAN Inc. Liman MYS versions from 2.2.3 to 2.3.1, enabling unauthorized users to gain elevated permissions. This matters because it can lead to severe system compromise and data breaches.","exploitability":"Exploitation is relatively straightforward given the missing authorization checks, requiring an attacker with access to the affected version of Liman MYS.","blast_radius":"If exploited, this vulnerability could have a wide impact, potentially allowing attackers to fully control the system and access sensitive data or critical functions.","remediation":"Update to Liman MYS version 2.3.1 or later to address the missing authorization issue.","tags":["auth-bypass","priv-escalation","ics"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T06:46:09.751Z"}}