CVE-2026-80444
Deferred Deferred - Pending Action

Open Redirect Vulnerability in AVESİS

Vulnerability report for CVE-2026-80444, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-23

Last updated on: 2026-09-23

Assigner: Computer Emergency Response Team of the Republic of Turkey

Description

URL redirection to untrusted site ('open redirect') vulnerability in Abis Technology Ltd. Co. AVESİS allows Input Data Manipulation. This issue affects AVESİS: from 202608201331 before 202608240351.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-23
Last Modified
2026-09-23
Generated
2026-09-24
AI Q&A
2026-09-23
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
abis_technology_ltd_co avesis From 202608201331 (inc) to 202608240351 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-601 The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an open redirect vulnerability in Abis Technology Ltd. Co. AVESİS software. It allows attackers to manipulate input data to redirect users to untrusted websites. The flaw exists between versions from 202608201331 and before 202608240351.

Detection Guidance

This vulnerability is an open redirect issue in Abis Technology Ltd. Co. AVESİS. Detection typically involves checking for improper URL validation in web applications. Look for URLs that redirect to external domains without proper validation. Manually test by appending different domains to the application's URL and observe if redirection occurs. Use browser developer tools to inspect network requests for suspicious redirect patterns.

Impact Analysis

Attackers could trick users into visiting malicious sites via legitimate-looking links. This may lead to phishing attacks, credential theft, or malware downloads. Users might unknowingly expose sensitive data or compromise their systems.

Compliance Impact

This vulnerability could violate data protection requirements under GDPR and HIPAA by enabling unauthorized data exposure or access. Organizations using affected AVESİS versions may face compliance failures and potential regulatory penalties.

Mitigation Strategies

Update AVESIS to a version after 202608240351 to address the open redirect vulnerability. Validate all user inputs to ensure they do not redirect to untrusted sites.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-80444. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart