Missing Authentication for Critical Function, Improper Access Control vulnerability in Dinosoft Business Solutions Dinosoft ERP allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Dinosoft ERP: from < 3.0.1 through 11022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
History

Wed, 11 Feb 2026 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 11 Feb 2026 12:45:00 +0000

Type Values Removed Values Added
Description Missing Authentication for Critical Function, Improper Access Control vulnerability in Dinosoft Business Solutions Dinosoft ERP allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Dinosoft ERP: from < 3.0.1 through 11022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Title Improper Access Control in Dinosoft Business Solutions' Dinosoft ERP
Weaknesses CWE-284
CWE-306
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: TR-CERT

Published:

Updated: 2026-02-11T14:38:21.755Z

Reserved: 2025-07-22T08:54:05.418Z

Link: CVE-2025-8025

cve-icon Vulnrichment

Updated: 2026-02-11T14:38:18.351Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-02-11T13:15:58.777

Modified: 2026-02-11T15:27:26.370

Link: CVE-2025-8025

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.