CVE-2025-9062: Mecode Informatics And Engineering Services Ltd Envanty
High severity, CVSS 7.3. EPSS: 0.2% chance of exploitation in the next 30 days.
Authorization Bypass Through User-Controlled Key vulnerability in MeCODE Informatics and Engineering Services Ltd. Envanty allows Parameter Injection. This issue affects Envanty: before 1.0.6. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. The vulnerability was learned to be remediated through reporter information and testing.
Affected products
- Mecode Informatics And Engineering Services Ltd Envanty: before 1.0.6 (fixed in 1.0.6)
Published 2026-02-19. Last modified 2026-06-17.