HIGH
Idurar
CVE published 2026-08-11
CVE-2026-72600
A broken access control vulnerability in Idurar IDURAR ERP CRM 4.1.0 allows unauthenticated remote attackers to download invoice PDF files containing customer PII via the /download router. The router is mounted without authentication middleware, making it publicly accessible. This vulnerability has significant implications for organizations using Idurar IDURAR ERP CRM 4.1.0, particularly those handling se [truncated]