Skip to content
Threat Feed
high advisory

Access Control Bypass in DetaWix Mobile Web Portal

The DetaWix Mobile Web Portal contains an improper access control vulnerability (CVE-2026-86450) that allows unauthenticated or unauthorized users to access sensitive functionality and exfiltrate data.

CVE search metadata

CVE search record: CVE-2026-86450. Severity: high. CVSS: 7.5. KEV: no. Product: DetaWix Mobile Web Portal (< 1.0.19). Brief: Access Control Bypass in DetaWix Mobile Web Portal. Brief link: https://feed.craftedsignal.io/briefs/2026-09-detawix-acl-bypass/

DetaWix Mobile Web Portal versions prior to 1.0.19 contain a critical vulnerability, tracked as CVE-2026-86450, involving the insertion of sensitive information into sent data. The root cause is a failure to properly constrain functionality via Access Control Lists (ACLs). This flaw allows unauthorized actors to interact with internal portal functions that should otherwise be restricted. Exploitation of this vulnerability could lead to the exposure of sensitive PII or business information. Organizations utilizing the DetaWix platform must prioritize patching to version 1.0.19 or later to mitigate the risk of data exposure.

Impact

Successful exploitation allows unauthorized access to restricted application functions. This can lead to the exfiltration of sensitive information processed by the DetaWix Mobile Web Portal. The scope of impact includes potential unauthorized data access within automotive trading environments where this portal is deployed.

Recommendation

  • Patch the DetaWix Mobile Web Portal to version 1.0.19 or later immediately.
  • Audit access logs for anomalous requests directed at restricted API endpoints or administrative functionalities within the portal.
  • Review web server logs for high-frequency requests from non-authenticated sessions targeting sensitive data paths.

Immediate actions

Upgrade DetaWix Mobile Web Portal to version 1.0.19 or later.

IT Operations 48h

Mitigations

Upgrade to v1.0.19 or later.

immediate IT Operations

CVE-2026-86450