Vulnerability Description
A vulnerability has been found in Bdtask SalesERP up to 20260116. This issue affects some unknown processing of the component Administrative Endpoint. Such manipulation of the argument ci_session leads to improper authorization. The attack may be performed from remote. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Bdtask | Saleserp | 2026-01-16 |
Related Weaknesses (CWE)
References
- https://github.com/4m3rr0r/PoCVulDb/issues/11ExploitIssue TrackingThird Party Advisory
- https://vuldb.com/?ctiid.343359Permissions RequiredVDB Entry
- https://vuldb.com/?id.343359Third Party AdvisoryVDB Entry
- https://vuldb.com/?submit.740735Third Party AdvisoryVDB Entry
- https://www.youtube.com/watch?v=KSducixS3pkExploit
FAQ
What is CVE-2026-1597?
CVE-2026-1597 is a vulnerability with a CVSS score of 6.3 (MEDIUM). A vulnerability has been found in Bdtask SalesERP up to 20260116. This issue affects some unknown processing of the component Administrative Endpoint. Such manipulation of the argument ci_session lead...
How severe is CVE-2026-1597?
CVE-2026-1597 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-1597?
Check the references section above for vendor advisories and patch information. Affected products include: Bdtask Saleserp.