CVE-2026-18642: Tubitak Bilgem Software Technologies Research Institute Eta-OTP-Lock
High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.
Deserialization of untrusted data vulnerability in TUBITAK BILGEM Software Technologies Research Institute eta-otp-lock allows Object Injection. This issue affects eta-otp-lock: before 1.0.4.
Affected products
- Tubitak Bilgem Software Technologies Research Institute Eta-OTP-Lock: before 1.0.4 (fixed in 1.0.4)
Published 2026-08-03. Last modified 2026-08-26.