CVE-2026-8323
A critical open redirect flaw lets attackers send users to malicious sites. The bug is in Armiya Information Technologies' Access Control System before version 2 and can be triggered over the network without authentication.
No official fix yet. If none appears within 45 days of first tracking, this entry is removed automatically.
Who is affected
Armiya Information Technologies Ltd. Co. Access Control System, versions prior to Versiyon 2.
Real-world impact
An attacker can trick users into visiting a malicious website, potentially leading to phishing, malware downloads, or credential theft.
Why this severity
The CVSS score of 9.3 reflects that the flaw is network‑accessible, requires no authentication or privilege, and can cause complete compromise of confidentiality. The vector shows no authentication or privilege needed, and the impact is high on confidentiality and integrity.
What to do about it
No official fix or mitigation is documented in the sources yet. Monitor the vendor advisory and apply the patch as soon as it is released.
No fix documented in sources