CVE-2026-10597: Itpison Omicard Edm

Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.

OMICARD EDM developed by ITPison has a Insecure Direct Object Reference vulnerability, allowing unauthenticated remote attackers to modify a specific parameter to obtain user's email address.

Affected products

  • Itpison Omicard Edm: from 5.8, up to and including 6.0.5.8

Published 2026-06-04. Last modified 2026-07-22.