CVE-2026-100903
Received Received - Intake

Missing Authentication in GEOritm REST API

Vulnerability report for CVE-2026-100903, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-28

Last updated on: 2026-09-28

Assigner: VulDB

Description

A vulnerability was identified in ООО НПО Ритм GEOritm up to 2.45.1. This affects an unknown part of the file /restapi/objects/obj-groups of the component REST API. Such manipulation of the argument objectId leads to missing authentication. The attack can be launched remotely. The exploit is publicly available and might be used. Upgrading to version 2.46 is able to mitigate this issue. It is advisable to upgrade the affected component. The vendor confirms: "In August 2026, NPO Ritm received an official vulnerability notification from the Russian Federal Service for Technical and Export Control (FSTEC Russia). The vulnerability was registered under identifier BDU:2026-11235. Following our internal investigation, we confirmed the vulnerability and implemented the necessary security fixes. The vulnerability has been fixed on our hosted GEO.RITM server at geo.ritm.ru. The fix has also been included in GEO.RITM version 2.46, which is already being distributed to our customers."

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-28
Last Modified
2026-09-28
Generated
2026-09-28
AI Q&A
2026-09-28
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
npo_ritm georitm to 2.45.1 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a missing authentication issue in the GEO.RITM REST API up to version 2.45.1. It allows remote attackers to access sensitive data without authentication by manipulating the objectId argument in the /restapi/objects/obj-groups endpoint. The flaw enables enumeration of vehicle fleet data and reading personal information like driver details and telemetry.

Detection Guidance

Check for unauthorized access attempts to the /restapi/objects/obj-groups endpoint. Monitor logs for requests to this path without valid authentication tokens. Use network traffic analysis tools to detect unusual POST requests to GEOritm REST API endpoints.

Impact Analysis

Unauthenticated access to sensitive data could expose personal information such as driver identities, vehicle locations, and fleet details. Attackers might use this to track vehicles, gather PII, or plan further attacks. The exploit is publicly available, increasing the risk of misuse.

Compliance Impact

This vulnerability likely violates data protection requirements under GDPR and HIPAA by exposing personal data without proper authentication. Organizations using affected versions may face compliance violations, legal penalties, and reputational damage due to unauthorized data access.

Mitigation Strategies

Upgrade GEOritm to version 2.46 or later. Ensure all instances of the software are updated to the patched version. Review and restrict access to the REST API endpoints. Monitor for any suspicious activity related to this vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-100903. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart