CVE-2026-17070: high-severity vulnerability in HAVELSAN Inc. Liman MYS
Vault Credential Confusion via Authorization Bypass in HAVELSAN's Liman MYS
Published
21Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 8.8epss 0.4%
exploitation probability
0.4%top 66% of all CVEs
observed exploitation
nono source reports it
Missing Authorization vulnerability in HAVELSAN Inc. Liman MYS allows Accessing Functionality Not Properly Constrained by ACLs.
This issue affects Liman MYS: from 2.2.3 before 2.3.1.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
HAVELSAN Inc. · Liman MYSRelated CVEs — HAVELSAN Inc. Liman MYS
In the same product, most dangerous first.
CVE-2026-13696HIGHLDAP Injection in HAVELSAN's Liman MYSEPSS 0.5%CVE-2026-18650HIGHMissing Authorization Leading to Root Code Execution in HAVELSAN's Liman MYSEPSS 0.4%CVE-2026-11340HIGHAuthorization Bypass in HAVELSAN's Open Source Project Liman MYSEPSS 0.4%CVE-2026-19532MEDIUMPath Traversal in HAVELSAN's Liman MYSEPSS 0.3%CVE-2026-11348HIGHAuthentication Bypass in HAVELSAN's Open Source Project Liman MYSEPSS 0.3%