CVE-2026-3263: GO2ISMAIL ASP.NET-Core-Inventory-Order-Management-System
High severity, CVSS 8.8. EPSS: 0.5% chance of exploitation in the next 30 days.
A vulnerability was found in go2ismail Asp.Net-Core-Inventory-Order-Management-System up to 9.20250118. Affected by this vulnerability is an unknown functionality of the file /api/Security/ of the component Security API. Performing a manipulation results in improper authorization. Remote exploitation of the attack is possible. The vendor was contacted early about this disclosure but did not respond in any way.
Affected products
- GO2ISMAIL ASP.NET-Core-Inventory-Order-Management-System: up to and including 9.20250118
Published 2026-02-26. Last modified 2026-06-17.