CVE-2026-13724
Deferred Deferred - Pending Action

Corporate Training System Client-Side Security Bypass

Vulnerability report for CVE-2026-13724, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-20

Last updated on: 2026-07-20

Assigner: Computer Emergency Response Team of the Republic of Turkey

Description

Client-Side Enforcement of Server-Side Security vulnerability in Gobito Informatics Technologies Engineering Industry and Trade Ltd. Co. Corporate Training Management System allows Input Data Manipulation. This issue affects Corporate Training Management System: before dd1a9df64.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-20
Last Modified
2026-07-20
Generated
2026-07-21
AI Q&A
2026-07-20
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
gobito_informatics_technologies_engineering_industry_and_trade_ltd_co corporate_training_management_system to dd1a9df64 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-602 The product is composed of a server that relies on the client to implement a mechanism that is intended to protect the server.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a client-side enforcement issue in Gobito's Corporate Training Management System. It allows attackers to manipulate input data even though security checks are supposed to be enforced on the server side. This could lead to unauthorized changes in the system's behavior or data.

Detection Guidance

This vulnerability involves client-side enforcement of server-side security, allowing input data manipulation. To detect it, inspect network traffic for unauthorized data modifications between client and server. Check application logs for unusual input patterns or requests bypassing server-side validation. Review client-side code for missing or weak input sanitization.

Impact Analysis

An attacker could exploit this to alter training records, bypass security controls, or manipulate system behavior without proper authorization. This might result in incorrect training data, unauthorized access, or compliance violations depending on the system's use.

Compliance Impact

This vulnerability could lead to data integrity issues, unauthorized access, or improper record-keeping, which may violate compliance requirements for GDPR, HIPAA, or other regulations that mandate accurate and secure data handling.

Mitigation Strategies

Update the Corporate Training Management System to the latest version or commit dd1a9df64 to address the client-side enforcement issue.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-13724. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart