The only editorial note is cut off mid-URL ("...guvenlik-bildirimleri/de"), so I don't have the replacement URL. I've left the USOM link as-is rather than guess at a substitute; that would mean inventing a source URL, and it also conflicts with your "keep every existing source URL" constraint. Send me the full replacement and I'll swap it in. Nothing else in the notes flagged any other change, so the body below is otherwise intact.
CVE-2026-8323: Critical Open Redirect in Armiya Access Control System
A critical-severity open redirect flaw (CVSS 9.3) in Armiya Information Technologies Ltd. Co. Access Control System lets attackers spoof the source of data by redirecting users to untrusted sites.
What Is It
CVE-2026-8323 is a URL redirection to untrusted site vulnerability, an open redirect, tracked as CWE-601, in Armiya Information Technologies Ltd. Co. Access Control System. According to the advisory, the issue "allows Fake the Source of Data," meaning an attacker can abuse the redirect to make attacker-controlled content appear to originate from the trusted access control application.
The CVE was published on 2026-09-10 by USOM (Turkey's national CERT, [email protected]), which is also the assigning source for the CVSS score. The record currently sits in Received status in NVD.
Why It Matters
The CVSS 3.1 base score is 9.3 (CRITICAL), with vector AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N.
That breaks down to: network-reachable, low attack complexity, and no privileges required. The attacker does need user interaction, a victim has to follow the crafted link, but the scope is changed, and both confidentiality and integrity impacts are rated HIGH. Availability is unaffected.
The combination of no authentication, low complexity, and a scope change is what pushes an open redirect into critical territory here: the flaw's effect reaches beyond the vulnerable component itself. For a physical/logical access control product, a convincing spoof of the trusted origin would plausibly lend itself to phishing aimed at credentials or session tokens, though the advisory describes no specific exploitation path and no such activity has been reported.
What's Vulnerable
- Vendor: Armiya Information Technologies Ltd. Co.
- Product: Access Control System
- Affected versions: all versions before Versiyon 2 (default status for other versions is
unaffected)
No CPE entries have been published for this CVE yet, so automated inventory matching will not currently flag affected assets. Identification has to be done by vendor and product name.
Patch Status
The affected version range is bounded at Versiyon 2, indicating that Versiyon 2 and later are not affected. Upgrading Access Control System to Versiyon 2 or later is the indicated remediation.
No CISA KEV entry was supplied for CVE-2026-8323, so there is no confirmation of active exploitation and no KEV-mandated remediation deadline at this time. Consult the USOM advisory below for vendor-specific guidance.
Sources
- NVD, CVE-2026-8323: https://nvd.nist.gov/vuln/detail/CVE-2026-8323
- USOM (siberguvenlik.gov.tr) advisory TR-26-1061: https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-1061