Sceawere

Vulnerability Detail

CVE-2026-86450UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

DetaWix Portal Information Disclosure Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
11h ago
Vendor
Parla Auto Automotive Trading Limited…
Product
DetaWix Mobile Web Portal
Attack Type
CWE-201 Insertion of sensitive information into sent data
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Insertion of sensitive information into sent data vulnerability in Parla Auto Automotive Trading Limited Company DetaWix Mobile Web Portal allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects DetaWix Mobile Web Portal: before v1.0.19.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-09-29T14:17:21.763Z",
  "pubdate": "2026-09-29T14:17:21.763Z",
  "executiveSummary": "DetaWix Mobile Web Portal is affected by a critical vulnerability involving the insertion of sensitive information into transmitted data packets and an authorization bypass due to insufficient Access Control List (ACL) enforcement.\nThis vulnerability, present in versions prior to 1.0.19, allows unauthorized entities to gain access to protected administrative or user-specific functionality.\nThe risk implication is significant, as it exposes internal data structures and sensitive information through improper data handling practices.\nThe vulnerability allows an unauthenticated or low-privileged attacker to leverage the lack of server-side constraints to interact with sensitive API endpoints or web functions that should be restricted.\nSuccessful exploitation could lead to unauthorized data retrieval, potentially exposing PII or internal system configuration details, compromising the confidentiality and integrity of the automotive trading platform.",
  "technicalDetails": "The vulnerability originates from two primary security failures within the DetaWix Mobile Web Portal application: an insecure data transmission mechanism and a failure to enforce authorization checks at the functional level.\nRoot Cause Analysis: The application incorrectly includes sensitive metadata or internal data within the outgoing response payloads, which may be intercepted or parsed by unauthorized actors. Concurrently, the server-side architecture fails to perform comprehensive ACL checks for specific sensitive functions, effectively rendering those functions public or semi-public regardless of the user's current session state or privilege level.\nAttack Flow: An attacker begins by enumerating the web portal's API endpoints or web functions. Upon identifying the sensitive functionality, the attacker bypasses the client-side UI restrictions that normally guard these features. Because the backend infrastructure lacks robust ACL enforcement, the server processes the request as if it were a valid, authorized action. During this interaction, the server transmits sensitive information—which is inadvertently embedded in the response—back to the attacker’s machine.\nAuthentication and Authorization: The vulnerability exists because the backend application relies on client-side state or implicit trust rather than explicit, server-side identity and permission validation for every API call. Consequently, an attacker does not require specific credentials if the function is exposed globally without a mandatory authorization middleware check.\nAffected Components: The issue is systemic, likely residing in the application's request-handling pipeline and the controller logic responsible for processing data requests within the Mobile Web Portal interface. Affected versions include all deployments prior to v1.0.19.\nExploitation and Post-Exploitation: By crafting specific HTTP requests to the identified vulnerable endpoints, an attacker can exfiltrate sensitive data streams. The impact of such exploitation extends to the unauthorized modification or extraction of automotive trading data, potential PII leakage, and further reconnaissance into the underlying infrastructure, as the improperly constrained functionality may lead to secondary vulnerabilities such as Insecure Direct Object References (IDOR) or unauthorized state changes."
}
CVE-2026-86450: DetaWix Portal Information Disclosure Vulnerability (HIGH Severity, CVSS: 7.5) | Sceawere