ZeroHour

CVE-2026-19616

Unauthenticated Missing-Authorization Flaw in TBC Technology KitLogistic

CVSS 3.1
7.5 high
EPSS
<1%p15
Published
()
Modified
AI analysis

CVE-2026-19616 is a missing-authorization flaw (CWE-862) in TBC Technology Inc.'s KitLogistic that allows access to functionality not properly constrained by access-control checks. It is triggerable remotely over a network by an unauthenticated attacker with no user interaction and no special conditions (CVSS:3.1/AV:N/AC:L/PR:N/UI:N). An attacker who reaches the unprotected functions gains unauthorized access to sensitive information — the CVSS scoring indicates high confidentiality impact with no integrity or availability impact, so this is an information-disclosure class issue. Any deployment running KitLogistic versions prior to v2.2.2 is affected. There is currently no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.2% probability of exploitation in the next 30 days, indicating no known exploitation activity.

What to do: Upgrade KitLogistic to v2.2.2 or later, which contains the authorization fix. If upgrading is not immediately possible, restrict network access to the affected service (e.g., firewall/ACL rules or WAF) and review access logs for unauthenticated requests to sensitive endpoints. Because the flaw is information-disclosure oriented, verify what data the exposed functions return and treat any anomalous read access as potential data exposure.

Affected
TBC Technology Inc. KitLogisticall versions before v2.2.2
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Missing Authorization vulnerability in TBC Technology Inc. KitLogistic allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects KitLogistic: before v2.2.2.

Weakness
CWE-862
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.