CVE-2026-71809
Awaiting Analysis Awaiting Analysis - Queue

Authentication Bypass in Siam Ordering Server

Vulnerability report for CVE-2026-71809, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-14

Assigner: MITRE

Description

Authentication Bypass via Hardcoded Master Verification Code vulnerability in Siam Ordering (siam-server) 1.0.0 allows remote unauthenticated attackers to log in as any user, merchant, or administrator.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-14
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-29
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
siam siam-server 1.0.0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-259 The product contains a hard-coded password, which it uses for its own inbound authentication or for outbound communication to external components.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Authentication Bypass via Hardcoded Master Verification Code in Siam Ordering (siam-server) version 1.0.0. It allows remote unauthenticated attackers to log in as any user, merchant, or administrator without needing valid credentials.

Detection Guidance

Check Siam Ordering system logs for repeated login attempts using the hardcoded verification code '123456'. Inspect Java service files (AdminServiceImpl.java, MerchantServiceImpl.java, MemberServiceImpl.java) for hardcoded SMS verification logic. Monitor network traffic for authentication bypass attempts targeting login or password recovery endpoints.

Impact Analysis

An attacker could gain full access to user accounts, merchant systems, or administrative functions. This may lead to unauthorized data access, modification, or deletion, as well as potential control over the entire system.

Compliance Impact

This vulnerability likely violates compliance requirements for data protection and access control under standards like GDPR and HIPAA. It enables unauthorized access to sensitive data, which could result in legal penalties, data breaches, and loss of trust.

Mitigation Strategies

Immediately update Siam Ordering (siam-server) to the latest patched version. If no patch is available, consider disabling the service until a fix is released. Review all authentication logs for suspicious activity and revoke any unauthorized sessions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-71809. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart