PatchSiren

NPO Ritm CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM NPO Ritm CVE published 2026-09-28

CVE-2026-100903

A vulnerability was identified in ООО НПО Ритм GEOritm up to 2.45.1, affecting an unknown part of the file /restapi/objects/obj-groups of the component REST API. Manipulation of the argument objectId leads to missing authentication, allowing remote attacks. Upgrading to version 2.46 mitigates this issue. The vendor confirms the vulnerability and has implemented security fixes in version 2.46, which is bei [truncated]