In un mondo digitale in cui ogni nuovo servizio online allarga la superficie di attacco, i Penetration Test non sono più solo un “check di sicurezza”, ma uno strumento essenziale per capire quanto le nostre infrastrutture reggano davvero sotto pressione.
| Field |
Value |
| CVE ID |
CVE-2026-51367 |
| Product |
Vedo Suite (Bottinelli Informatica) |
| Affected Version(s) |
v1.2.5 |
| Vulnerability Class |
CWE-639: Authorization Bypass Through User-Controlled Key |
| Attack Vector |
Network (HTTP API) |
| Privileges Required |
Low (authenticated application user) |
| User Interaction |
None |
| Impact |
Confidentiality breach / unauthorized access to other users’ data |
| Estimated CVSS 3.1 |
8.7 (High) — AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
| Estimated CVSS 3.1 |
9.9 (Critical) — AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
| Field |
Value |
| CVE ID |
CVE-2026-51366 |
| Product |
Vedo Suite (Bottinelli Informatica) |
| Affected Version(s) |
v1.2.5 (and possibly earlier/other versions using the same endpoint logic — unconfirmed) |
| Vulnerability Class |
CWE-89: SQL Injection |
| Secondary Impact |
CWE-78: OS Command Injection (via xp_cmdshell) |
| Attack Vector |
Network (HTTP GET) |
| Privileges Required |
Low (authenticated application user) |
| User Interaction |
None |
| Backend |
Microsoft SQL Server |
| Estimated CVSS 3.1 |
9.9 (Critical) — AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |