CVE-2026-10711
Deferred
Deferred - Pending Action
Authentication Bypass in CafePlus Software
Publication date: 2026-06-23
Last updated on: 2026-06-23
Assigner: Computer Emergency Response Team of the Republic of Turkey
Description
Description
Missing authentication for critical function vulnerability in AKIN Software Computer Import Export Industry and Trade Ltd. CafePlus allows Accessing Functionality Not Properly Constrained by ACLs.
This issue affects CafePlus: from 12.05.03 before 12.05.04.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| akin_software | cafeplus | From 12.05.03 (inc) to 12.05.04 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-306 | The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources. |