ZeroHour

CVE-2026-8323

Open Redirect in Armiya Access Control System prior to Version 2

CVSS 3.1
9.3 critical
EPSS
Published
()
Modified
AI analysis

CVE-2026-8323 is an open redirect (CWE-601) in the Armiya Information Technologies Access Control System, affecting all releases before Version 2. An attacker crafts a link to the system's legitimate URL containing a redirect parameter, and when a user clicks it (user interaction is required per the CVSS score), the browser is silently forwarded to an attacker-controlled site while the link still appears to point to the trusted system. Because the CVSS score indicates a scope change with high confidentiality and integrity impact, a successful redirect can let the attacker 'fake the source of data' — for example, presenting a spoofed login page that mimics the access control system to harvest credentials or session data. Organizations running affected versions of Armiya's Access Control System, typically at facilities using it for physical door access management, are exposed through the product's network-facing interface. There is currently no public proof-of-concept, the flaw is not in CISA's KEV catalog, and no exploitation is known.

What to do: Upgrade Armiya Access Control System to Version 2 (Versiyon 2) or later, which resolves the open redirect. Until then, restrict the system's web interface to trusted networks (e.g., VPN or internal-only) rather than exposing it to the internet, and caution users against clicking links to the system that arrive via email or messaging. Check whether your deployment's web login page is reachable from the internet, as that is the primary path for phishing-style abuse of this flaw.

Affected
Armiya Information Technologies Ltd. Co. Access Control Systemall versions before Version 2 (Versiyon 2)
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

URL redirection to untrusted site ('open redirect') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System allows Fake the Source of Data. This issue affects Access Control System: before Versiyon 2.

Weakness
CWE-601
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N

In the news

No ingested article mentions this CVE yet.