CVE-2026-18650
8.8 HIGHPublished 2026-08-04 · Updated 2026-08-04
AI risk analysis
- Summary
- The flaw is a missing authorization vulnerability that allows privilege escalation in HAVELSAN Inc. Liman MYS versions from 2.2.3 to 2.3.1, enabling unauthorized users to gain elevated permissions. This matters because it can lead to severe system compromise and data breaches.
- Exploitability
- Exploitation is relatively straightforward given the missing authorization checks, requiring an attacker with access to the affected version of Liman MYS.
- Blast radius
- If exploited, this vulnerability could have a wide impact, potentially allowing attackers to fully control the system and access sensitive data or critical functions.
- Prioritized remediation
- Update to Liman MYS version 2.3.1 or later to address the missing authorization issue.
auth-bypasspriv-escalationics
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Privilege Escalation. This issue affects Liman MYS: from 2.2.3 before 2.3.1.
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses
CWE-862
All references
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.