Sceawere

Vulnerability Detail

CVE-2026-66465UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Unauthenticated Broken Authentication in Cartify

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
7h ago
Vendor
AgniHD
Product
Cartify
Attack Type
CWE-288 Authentication Bypass Using an Alternate Path or Channel
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

Unauthenticated Broken Authentication in Cartify <= 1.3.0.1 versions.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-08-13T14:17:07.833Z",
  "pubdate": "2026-08-13T14:17:07.833Z",
  "executiveSummary": "An unauthenticated broken authentication vulnerability has been identified in Cartify versions <= 1.3.0.1. This security flaw allows unauthenticated remote attackers to bypass authentication mechanisms entirely, leading to unauthorized access to sensitive application functionalities and user accounts. The presence of this vulnerability poses severe risk implications, as it compromises the core security perimeter of the affected system without requiring prior credentials, specific interaction, or high privileges. Attackers can exploit this weakness directly over the network to interact with vulnerable endpoints improperly protected by the authentication architecture. Immediate remediation is required to restore secure identity verification and access control enforcement within the application.",
  "technicalDetails": "The vulnerability stems from flawed implementation and enforcement of authentication checks within the affected versions of Cartify <= 1.3.0.1. The root cause lies in the application's failure to properly validate user sessions or cryptographic tokens across critical application routes, or the complete absence of session validation logic on sensitive functional components. Specifically, the vulnerable component fails to enforce mandatory authentication barriers, allowing arbitrary unauthenticated HTTP requests to successfully invoke backend functions intended solely for authenticated users.\nFrom a network exposure perspective, the vulnerable endpoints are accessible remotely via standard web protocols, requiring no prior positioning inside the internal network topology. Attackers operate with zero privileges, bypassing the authentication phase entirely by directly crafting and submitting requests to vulnerable application endpoints or manipulating session states due to weak token generation or validation routines.\nThe attack flow proceeds as follows: First, the unauthenticated actor identifies target application routes or functions that lack adequate security enforcement. Second, the attacker crafts a malicious HTTP request directed at these protected endpoints, omitting valid authentication headers, cookies, or tokens, or supplying forged identifiers. Third, the backend application processes the request without verifying the authenticity or authorization level of the caller. Finally, the application executes the requested operation, granting the attacker unauthorized access to privileged resources, sensitive data views, or administrative capabilities.\nThe post-exploitation impact includes complete loss of confidentiality and integrity of the affected application environment. Depending on the specific functions exposed, successful exploitation can result in unauthorized data exfiltration, modification of application settings, or total administrative takeover of the underlying system architecture."
}
CVE-2026-66465: Unauthenticated Broken Authentication in Cartify (CRITICAL Severity, CVSS: 9.8) - Sceawere