CRITICAL🇵🇱 Wersja polska

CVE-2026-1363

CVSS 9.3v4.0pub. 2026-01-23upd. 2026-04-15

IAQS and I6 developed by JNC has a Client-Side Enforcement of Server-Side Security vulnerability, allowing unauthenticated remote attackers to gain administrator privileges by manipulating the web front-end.

🤖 AI Analysis
How it works

Access control logic is enforced only on the client side (web interface) and not on the server side. An attacker can manipulate requests sent to the web application — for example, by modifying parameters, headers, or form data — to bypass permission verification. As a result, the server accepts administrative operations without verifying whether the requesting user has appropriate permissions.

Impact

Attacker gains full administrator privileges in the system, enabling them to read, modify, or delete data and take control of the application. The vulnerability is exploitable remotely without authentication, making it particularly dangerous in network-accessible environments.

Mitigation & patch

Apply patches available from the manufacturer in accordance with references published by TWCERT: https://www.twcert.org.tw/en/cp-139-10653-117a1-2.html and https://www.twcert.org.tw/tw/cp-132-10652-4cdca-1.html. Until the fix is deployed, it is recommended to restrict access to the web interface to trusted networks or IP addresses only through a firewall.

Who is affected

IAQS and I6 products from JNC — versions specified in manufacturer references (TWCERT).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
References