CVE-2026-3263: GO2ISMAIL ASP.NET-Core-Inventory-Order-Management-System

High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.

A vulnerability was found in go2ismail Asp.Net-Core-Inventory-Order-Management-System up to 9.20250118. Affected by this vulnerability is an unknown functionality of the file /api/Security/ of the component Security API. Performing a manipulation results in improper authorization. Remote exploitation of the attack is possible. The vendor was contacted early about this disclosure but did not respond in any way.

Affected products

  • GO2ISMAIL ASP.NET-Core-Inventory-Order-Management-System: up to and including 9.20250118

Published 2026-02-26. Last modified 2026-06-17.