Description
SirenGPS Android Application 2.19.44 is vulnerable to Incorrect Access Control. An authenticated attacker can manipulate user identifier parameters to bypass authorization controls and gain unauthorized READ and WRITE access to other users' personal information. The API fails to validate that the requesting user is authorized to access the target user's data.
Published:
2026-08-05
Score:
n/a
EPSS:
n/a
KEV:
No
Impact:
n/a
Action:
n/a
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
No advisories yet.
References
History
Wed, 05 Aug 2026 23:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | Incorrect Access Control Allows Bypassing Authentication in SirenGPS Android App | |
| Weaknesses | CWE-284 |
Wed, 05 Aug 2026 22:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | SirenGPS Android Application 2.19.44 is vulnerable to Incorrect Access Control. An authenticated attacker can manipulate user identifier parameters to bypass authorization controls and gain unauthorized READ and WRITE access to other users' personal information. The API fails to validate that the requesting user is authorized to access the target user's data. | |
| References |
|
Subscriptions
No data.
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2026-08-05T21:52:45.164Z
Reserved: 2025-10-27T00:00:00.000Z
Link: CVE-2025-63822
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-05T23:30:04Z
Weaknesses
-
CWE-284
Improper Access Control