CVE-2025-9986

8.2

Vadi Corporate Information Systems Ltd · DIGIKENT

A vulnerability in Vadi Corporate Information Systems Ltd DIGIKENT allows unauthenticated attackers to access sensitive system information.

Executive summary

The DIGIKENT system is vulnerable to an information exposure flaw that allows unauthorized parties to access sensitive data without authentication.

Vulnerability

This vulnerability, categorized as CWE-497, permits an unauthenticated remote attacker to retrieve sensitive system configuration or operational information due to improper exposure to an unauthorized control sphere.

Business impact

The exposure of sensitive system information can provide attackers with the reconnaissance data necessary to launch more sophisticated, targeted attacks against the internal infrastructure. Given the CVSS score of 8.2, this vulnerability represents a high risk to the confidentiality of organizational data. Unauthorized access to system details may lead to a breach of sensitive information, potentially resulting in regulatory non-compliance and reputational damage.

Remediation

Immediate Action: Review the official security advisory from USOM (TR-26-0056) for patch availability and apply all recommended updates to the DIGIKENT platform immediately.

Proactive Monitoring: Monitor network traffic and system access logs for unusual patterns or unauthorized requests directed at administrative or configuration endpoints.

Compensating Controls: Implement strict access control lists or place the DIGIKENT application behind a Web Application Firewall (WAF) to restrict external access to sensitive directories and prevent unauthorized data retrieval.

Exploitation status

Public Exploit Available: Unknown.

Analyst recommendation

The high CVSS score of 8.2 necessitates immediate attention from IT and security administrators. Organizations utilizing the DIGIKENT platform should prioritize identifying affected instances and applying vendor-supplied updates as soon as they become available. In the interim, ensure that the application is not unnecessarily exposed to the public internet to mitigate the risk of unauthorized information disclosure.

More Vadi Corporate Information Systems Ltd CVEs

Sources

Originally found and disclosed by Ferhat UÇAR, per the CVE Program record.