PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-9410 Sushmi-pal CVE debrief

A low-severity improper authorization vulnerability in Sushmi-pal Invoice-System allows authenticated remote attackers to manipulate the ID parameter in the /profile endpoint, potentially leading to unauthorized access within the Profile Workflow component. The vulnerability affects versions up to commit a0a3faa16dee2621b231ae227333f5761607283b. The vendor was contacted but did not respond, and exploit details have been publicly disclosed.

Vendor
Sushmi-pal
Product
Invoice-System
CVSS
LOW 2.1
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-25
Original CVE updated
2026-07-23
Advisory published
2026-05-25
Advisory updated
2026-07-23

Who should care

Organizations using Sushmi-pal Invoice-System for invoice management; security teams monitoring for IDOR vulnerabilities in PHP-based web applications; developers implementing authorization controls in similar profile management workflows

Technical summary

The vulnerability exists in the Profile Workflow component's /profile endpoint where the ID parameter can be manipulated to bypass authorization controls. The application fails to properly validate that the requested profile ID belongs to the currently authenticated user, allowing authenticated attackers to potentially access or modify other users' profile information. The CVSS 4.0 score of 2.1 reflects limited integrity impact with no confidentiality or availability impact under the assessed vector.

Defensive priority

LOW

Recommended defensive actions

  • Review and implement proper authorization checks on the /profile endpoint, specifically validating that the ID parameter corresponds to the authenticated user's session
  • Implement resource-level access controls to ensure users can only access their own profile data
  • Consider adding indirect object reference mapping or additional session validation to prevent ID parameter manipulation
  • Monitor for anomalous access patterns to profile endpoints indicating potential exploitation attempts
  • Evaluate alternative invoice system solutions given vendor non-responsiveness to security disclosures

Evidence notes

Vulnerability identified through Vuldb submission 813606. CVSS 4.0 vector indicates network attack vector with low attack complexity, requiring low privileges but no user interaction. CWE-266 (Incorrect Privilege Assignment) and CWE-285 (Improper Authorization) classified as primary weakness types.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-9410 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-9410

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-9410 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-9410

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.