CVE-2026-71809

High severity, CVSS 8.1. EPSS: 0.6% chance of exploitation in the next 30 days.

Authentication Bypass via Hardcoded Master Verification Code vulnerability in Siam Ordering (siam-server) 1.0.0 allows remote unauthenticated attackers to log in as any user, merchant, or administrator.

Published 2026-09-09. Last modified 2026-09-14.