CVE-2026-8323
Deferred Deferred - Pending Action

Open Redirect in Armiya Access Control System

Vulnerability report for CVE-2026-8323, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-10

Last updated on: 2026-09-10

Assigner: Computer Emergency Response Team of the Republic of Turkey

Description

URL redirection to untrusted site ('open redirect') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System allows Fake the Source of Data. This issue affects Access Control System: before Versiyon 2.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-10
Last Modified
2026-09-10
Generated
2026-09-30
AI Q&A
2026-09-10
EPSS Evaluated
2026-09-29
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
armiya_information_technologies_ltd_co access_control_system to 2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-601 The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an open redirect vulnerability in Armiya Information Technologies Ltd. Co. Access Control System. It allows attackers to trick users into visiting malicious websites by manipulating URLs, making it appear as if they are coming from a trusted source.

Detection Guidance

This vulnerability involves an open redirect in Armiya Access Control System versions before 2. To detect it, inspect web application logs for unusual URL redirections to untrusted domains. Check HTTP responses for Location headers pointing to external sites. Test with crafted URLs containing redirect parameters to see if the system follows them to arbitrary domains.

Impact Analysis

Attackers could use this to steal sensitive information like login credentials or install malware. Users might unknowingly visit harmful sites, leading to phishing attacks or data breaches.

Compliance Impact

This vulnerability could lead to unauthorized data access or breaches, violating GDPR (data protection) and HIPAA (health information privacy) requirements. Organizations may face legal penalties and reputational damage.

Mitigation Strategies

Update the Access Control System to Version 2 or later to address the open redirect vulnerability. Ensure all instances are patched as this affects systems before Version 2.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-8323. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart