CVE-2026-10597
Deferred Deferred - Pending Action
Insecure Direct Object Reference in OMICARD EDM Exposes User Email

Publication date: 2026-06-04

Last updated on: 2026-06-04

Assigner: TWCERT/CC

Description
OMICARD EDM developed by ITPison has a Insecure Direct Object Reference vulnerability, allowing unauthenticated remote attackers to modify a specific parameter to obtain user's email address.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-04
Last Modified
2026-06-04
Generated
2026-06-24
AI Q&A
2026-06-04
EPSS Evaluated
2026-06-23
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
itpison omicard_edm From 5.8 (inc) to 6.0.5.8 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

CVE-2026-10597 is an Insecure Direct Object Reference (IDOR) vulnerability in OMICARD EDM versions 5.8 to 6.0.5.8 developed by ITPison.

This flaw allows unauthenticated remote attackers to modify a specific parameter in the application to obtain users' email addresses without proper authorization.

Impact Analysis

The vulnerability can lead to unauthorized disclosure of users' email addresses by allowing attackers to access this information remotely without authentication.

This exposure of personal information can increase the risk of phishing attacks, spam, and other privacy violations.

The vulnerability has a moderate risk level with a CVSS v3.1 base score of 5.3.

Mitigation Strategies

The vendor has not provided a public patch for this vulnerability yet.

Users are advised to contact ITPison, the vendor, for a solution or patch to mitigate the risk.

Compliance Impact

The vulnerability allows unauthenticated remote attackers to obtain users' email addresses by exploiting an Insecure Direct Object Reference (IDOR) flaw in OMICARD EDM. This unauthorized access to personal data could potentially lead to non-compliance with data protection regulations such as GDPR and HIPAA, which require safeguarding personal information against unauthorized access.

However, the provided information does not explicitly discuss the impact of this vulnerability on compliance with specific standards or regulations.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-10597. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart