CVE-2026-1597
Last modified
CVE-2026-1597 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. A vulnerability has been found in Bdtask SalesERP up to 20260116. This issue affects some unknown processing of the component Administrative Endpoint. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
A vulnerability has been found in Bdtask SalesERP up to 20260116. This issue affects some unknown processing of the component Administrative Endpoint. Such manipulation of the argument ci_session leads to improper authorization. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Metrics
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Bdtask | Saleserp | 2026-01-16 |
References
- https://github.com/4m3rr0r/PoCVulDb/issues/11Exploit, Issue Tracking, Third Party Advisory
- https://vuldb.com/?ctiid.343359Permissions Required, VDB Entry
- https://vuldb.com/?id.343359Third Party Advisory, VDB Entry
- https://vuldb.com/?submit.740735Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-1597?
How severe is CVE-2026-1597?
How do I fix CVE-2026-1597?
How Strix Helps
- Uncovering a hidden BOLA in Appsmith's snapshot logicStrix autonomously discovered a BOLA/IDOR vulnerability in Appsmith's snapshot deletion path.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-15962The Fluent Forms Pro Add On Pack plugin for WordPress is vul…8.8
- CVE-2026-15964The Single Sign On For TNG plugin for WordPress is vulnerabl…9.8
- CVE-2026-15966Permissive cross-domain security policy with untrusted domai…9.8
- CVE-2026-15967Insufficient session expiration vulnerability in Progress MO…9.8
- CVE-2026-15968Improper neutralization of input during web page generation …5.4
- CVE-2026-15969SGLang contains an unauthenticated RCE in /load_lora_adapter…9.8
- CVE-2026-15970Consul Community Edition and Consul Enterprise 1.20.1 throug…4.2
- CVE-2026-15971SGLang contains an RCE vulnerability when the optional dumpe…9.8
- CVE-2026-15972Consul Community Edition and Consul Enterprise 1.13.0 throug…7.5
- CVE-2026-15974SGLang contains an SSRF and local file read in the multimoda…6.5
- CVE-2026-15975GitLab has remediated an issue in GitLab CE/EE affecting all…7.5
- CVE-2026-15976SGLang contains a RCE vulnerability when attempting to load …9.8
Are you affected by CVE-2026-1597?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
