Sceawere

Vulnerability Detail

CVE-2026-100903UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

GEOritm Missing Authentication Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
5.3
Creation Date
4h ago
Vendor
ООО НПО Ритм
Product
GEOritm
Attack Type
Missing Authentication
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was identified in ООО НПО Ритм GEOritm up to 2.45.1. This affects an unknown part of the file /restapi/objects/obj-groups of the component REST API. Such manipulation of the argument objectId leads to missing authentication. The attack can be launched remotely. The exploit is publicly available and might be used. Upgrading to version 2.46 is able to mitigate this issue. It is advisable to upgrade the affected component. The vendor confirms: "In August 2026, NPO Ritm received an official vulnerability notification from the Russian Federal Service for Technical and Export Control (FSTEC Russia). The vulnerability was registered under identifier BDU:2026-11235. Following our internal investigation, we confirmed the vulnerability and implemented the necessary security fixes. The vulnerability has been fixed on our hosted GEO.RITM server at geo.ritm.ru. The fix has also been included in GEO.RITM version 2.46, which is already being distributed to our customers."

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "5.3",
  "pubDate": "2026-09-28T04:17:07.690Z",
  "pubdate": "2026-09-28T04:17:07.690Z",
  "executiveSummary": "A critical missing authentication vulnerability has been identified in the ООО НПО Ритм GEOritm platform, specifically affecting the REST API component.\nThe vulnerability, tracked as BDU:2026-11235, allows remote, unauthenticated attackers to interact with protected resources by manipulating the 'objectId' argument within the '/restapi/objects/obj-groups' endpoint.\nThe absence of proper access control checks enables unauthorized entities to bypass security protocols, potentially leading to unauthorized data access or system manipulation.\nGiven that exploit code is publicly available, the risk of active exploitation is significant for deployments running versions up to and including 2.45.1.\nSuccessful exploitation does not require prior authentication, significantly lowering the barrier for remote attackers to compromise the integrity and confidentiality of the GEOritm system.\nImmediate remediation is required, involving an upgrade to version 2.46, which contains the necessary security fixes for this flaw.",
  "technicalDetails": "The vulnerability resides within the REST API interface of the GEOritm platform, specifically targeting the /restapi/objects/obj-groups endpoint. The root cause is a failure in the application's authentication and authorization middleware to properly validate user credentials or session tokens when the 'objectId' parameter is specified in a request.\nUnder normal operating conditions, the /restapi/objects/obj-groups endpoint is intended to be protected by authentication headers or session-based cookies. However, the implementation of the API logic allows an attacker to bypass these checks by providing a maliciously crafted 'objectId' argument. The system fails to verify whether the requester has the appropriate permissions or a valid session prior to processing the request associated with the provided object identifier.\nThe attack flow proceeds as follows: An unauthenticated attacker sends a specially crafted HTTP request to the /restapi/objects/obj-groups URI. By manipulating the 'objectId' parameter, the attacker forces the backend component to process the request as if it originated from an authorized user. Because the underlying code lacks a mandatory authentication check for this specific API route, the system executes the backend function intended for legitimate administrative or user-based operations.\nThe technical impact of this vulnerability is severe, as it facilitates remote unauthorized access to sensitive objects managed by the GEOritm REST API. Attackers can leverage this bypass to retrieve, manipulate, or delete grouped objects without needing valid credentials. Because the endpoint handles structural object groups, an attacker may be able to gain visibility into the system's organizational hierarchy or manipulate data structures that govern system access or configuration.\nAffected versions include all releases of GEOritm up to and including 2.45.1. The vulnerability is network-reachable, meaning it can be exploited from any remote location capable of communicating with the REST API interface. The availability of public exploit material underscores the urgency of addressing the flaw, as it reduces the complexity required for an attacker to successfully compromise the application. The fix implemented in version 2.46 introduces mandatory authentication checks that ensure all requests to the affected API endpoints are validated against the identity of the requester before any object processing occurs."
}
CVE-2026-100903: GEOritm Missing Authentication Vulnerability (MEDIUM Severity, CVSS: 5.3) | Sceawere