CVE-2026-72600: Idurar ERP CRM

High severity, CVSS 7.5. EPSS: 0.6% chance of exploitation in the next 30 days.

A broken access control vulnerability in Idurar IDURAR ERP CRM 4.1.0 allows unauthenticated remote attackers to download invoice PDF files containing customer PII via the /download router. The router is mounted without authentication middleware, making it publicly accessible. An attacker can enumerate MongoDB ObjectIds to download any invoice in the system without credentials.

Affected products

  • Idurar Idurar ERP CRM: up to and including 4.1.0

Published 2026-08-11. Last modified 2026-09-03.