CVE-2026-72600
HIGH
NVD
CVSS Score
7.5
Severity
HIGH
Published
Aug 11, 2026
Vendor
unknown
Description
A broken access control vulnerability in Idurar IDURAR ERP CRM 4.1.0 allows unauthenticated remote attackers to download invoice PDF files containing customer PII via the /download router. The router is mounted without authentication middleware, making it publicly accessible. An attacker can enumerate MongoDB ObjectIds to download any invoice in the system without credentials.