CVE-2026-19616
—Unauthenticated Missing-Authorization Flaw in TBC Technology KitLogistic
CVE-2026-19616 is a missing-authorization flaw (CWE-862) in TBC Technology Inc.'s KitLogistic that allows access to functionality not properly constrained by access-control checks. It is triggerable remotely over a network by an unauthenticated attacker with no user interaction and no special conditions (CVSS:3.1/AV:N/AC:L/PR:N/UI:N). An attacker who reaches the unprotected functions gains unauthorized access to sensitive information — the CVSS scoring indicates high confidentiality impact with no integrity or availability impact, so this is an information-disclosure class issue. Any deployment running KitLogistic versions prior to v2.2.2 is affected. There is currently no known public proof-of-concept, the flaw is not in CISA's KEV catalog, and EPSS estimates only a 0.2% probability of exploitation in the next 30 days, indicating no known exploitation activity.
What to do: Upgrade KitLogistic to v2.2.2 or later, which contains the authorization fix. If upgrading is not immediately possible, restrict network access to the affected service (e.g., firewall/ACL rules or WAF) and review access logs for unauthenticated requests to sensitive endpoints. Because the flaw is information-disclosure oriented, verify what data the exposed functions return and treat any anomalous read access as potential data exposure.
| TBC Technology Inc. KitLogistic | all versions before v2.2.2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Missing Authorization vulnerability in TBC Technology Inc. KitLogistic allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects KitLogistic: before v2.2.2.
- Weakness
- CWE-862
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.