CVE-2026-4773
Deferred Deferred - Pending Action

Authentication Bypass in IDM-MFA via Input Validation Flaw

Vulnerability report for CVE-2026-4773, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-22

Last updated on: 2026-07-22

Assigner: Computer Emergency Response Team of the Republic of Turkey

Description

Improper validation of specified type of input vulnerability in Magarsus Consulting Ltd. Co. IDM-MFA allows Authentication Bypass. This issue affects IDM-MFA: from 2025.11.27 before 2026.03.10.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-22
Last Modified
2026-07-22
Generated
2026-08-11
AI Q&A
2026-07-22
EPSS Evaluated
2026-08-10
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
magarsus_consulting_ltd_co idm-mfa From 2025.11.27 (inc) to 2026.03.10 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-1287 The product receives input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is actually of the expected type.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an improper validation of input in Magarsus Consulting Ltd. Co. IDM-MFA that allows an attacker to bypass authentication. It affects versions from 2025.11.27 up to but not including 2026.03.10.

Detection Guidance

Detection methods are not specified in the provided CVE details. Focus on monitoring authentication bypass attempts and validate IDM-MFA versions against the affected range (before 2026.03.10).

Impact Analysis

An attacker could exploit this to bypass authentication, potentially gaining unauthorized access to sensitive systems or data protected by IDM-MFA.

Compliance Impact

The vulnerability allows authentication bypass, which could lead to unauthorized access to sensitive data. This may violate compliance requirements under GDPR (data protection) and HIPAA (health information security) by enabling unauthorized access to personal or health data.

Mitigation Strategies

Update IDM-MFA to version 2026.03.10 or later to address the improper input validation issue. Disable or restrict network access to the affected system until patched.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-4773. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart