← Back to search

CVE-2026-18650

8.8 HIGH

Published 2026-08-04 · Updated 2026-08-04

AI risk analysis

Summary
The flaw is a missing authorization vulnerability that allows privilege escalation in HAVELSAN Inc. Liman MYS versions from 2.2.3 to 2.3.1, enabling unauthorized users to gain elevated permissions. This matters because it can lead to severe system compromise and data breaches.
Exploitability
Exploitation is relatively straightforward given the missing authorization checks, requiring an attacker with access to the affected version of Liman MYS.
Blast radius
If exploited, this vulnerability could have a wide impact, potentially allowing attackers to fully control the system and access sensitive data or critical functions.
Prioritized remediation
Update to Liman MYS version 2.3.1 or later to address the missing authorization issue.
auth-bypasspriv-escalationics

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Privilege Escalation. This issue affects Liman MYS: from 2.2.3 before 2.3.1.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-862

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.