Stats Digest Feeds
โ† Back to all CVEs

CVE-2026-72600

HIGH NVD
CVSS Score 7.5
Severity HIGH
Published Aug 11, 2026
Vendor unknown

Description

A broken access control vulnerability in Idurar IDURAR ERP CRM 4.1.0 allows unauthenticated remote attackers to download invoice PDF files containing customer PII via the /download router. The router is mounted without authentication middleware, making it publicly accessible. An attacker can enumerate MongoDB ObjectIds to download any invoice in the system without credentials.

References