Security Advisory
CVE-2026-72600
7.5
HIGH
Vulnerability Description
A broken access control vulnerability in Idurar IDURAR ERP CRM 4.1.0 allows unauthenticated remote attackers to download invoice PDF files containing customer PII via the /download router. The router is mounted without authentication middleware, making it publicly accessible. An attacker can enumerate MongoDB ObjectIds to download any invoice in the system without credentials.
Published Date
August 11, 2026
Official Source
NIST NVD Advisory