{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/parla-auto-automotive-trading-limited-company/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:parla_auto_automotive_trading:detawix_mobile_web_portal:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-86450"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["DetaWix Mobile Web Portal (\u003c 1.0.19)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Parla Auto Automotive Trading Limited Company"],"content_html":"\u003cp\u003eDetaWix Mobile Web Portal versions prior to 1.0.19 contain a critical vulnerability, tracked as CVE-2026-86450, involving the insertion of sensitive information into sent data. The root cause is a failure to properly constrain functionality via Access Control Lists (ACLs). This flaw allows unauthorized actors to interact with internal portal functions that should otherwise be restricted. Exploitation of this vulnerability could lead to the exposure of sensitive PII or business information. Organizations utilizing the DetaWix platform must prioritize patching to version 1.0.19 or later to mitigate the risk of data exposure.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthorized access to restricted application functions. This can lead to the exfiltration of sensitive information processed by the DetaWix Mobile Web Portal. The scope of impact includes potential unauthorized data access within automotive trading environments where this portal is deployed.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003ePatch the DetaWix Mobile Web Portal to version 1.0.19 or later immediately.\u003c/li\u003e\n\u003cli\u003eAudit access logs for anomalous requests directed at restricted API endpoints or administrative functionalities within the portal.\u003c/li\u003e\n\u003cli\u003eReview web server logs for high-frequency requests from non-authenticated sessions targeting sensitive data paths.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-29T18:28:56Z","date_published":"2026-09-29T18:28:56Z","id":"https://feed.craftedsignal.io/briefs/2026-09-detawix-acl-bypass/","summary":"The DetaWix Mobile Web Portal contains an improper access control vulnerability (CVE-2026-86450) that allows unauthenticated or unauthorized users to access sensitive functionality and exfiltrate data.","title":"Access Control Bypass in DetaWix Mobile Web Portal","url":"https://feed.craftedsignal.io/briefs/2026-09-detawix-acl-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Parla Auto Automotive Trading Limited Company","version":"https://jsonfeed.org/version/1.1"}