🔐 CVE Alert

CVE-2026-100903

MEDIUM 5.3

ООО НПО Ритм GEOritm REST API obj-groups missing authentication

CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th

A vulnerability was identified in ООО НПО Ритм GEOritm up to 2.45.1. This affects an unknown part of the file /restapi/objects/obj-groups of the component REST API. Such manipulation of the argument objectId leads to missing authentication. The attack can be launched remotely. The exploit is publicly available and might be used. Upgrading to version 2.46 is able to mitigate this issue. It is advisable to upgrade the affected component. The vendor confirms: "In August 2026, NPO Ritm received an official vulnerability notification from the Russian Federal Service for Technical and Export Control (FSTEC Russia). The vulnerability was registered under identifier BDU:2026-11235. Following our internal investigation, we confirmed the vulnerability and implemented the necessary security fixes. The vulnerability has been fixed on our hosted GEO.RITM server at geo.ritm.ru. The fix has also been included in GEO.RITM version 2.46, which is already being distributed to our customers."

CWE CWE-306 CWE-287
Vendor ооо нпо ритм
Product georitm
Published Sep 28, 2026
Stay Ahead of the Next One

Get instant alerts for ооо нпо ритм georitm

Be the first to know when new medium vulnerabilities affecting ооо нпо ритм georitm are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N/E:P/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

ООО НПО Ритм / GEOritm
2.45.0 2.45.1

References

NVD ↗ CVE.org ↗ EPSS Data ↗
vuldb.com: https://vuldb.com/vuln/410853 vuldb.com: https://vuldb.com/vuln/410853/cti vuldb.com: https://vuldb.com/cve/CVE-2026-100903 vuldb.com: https://vuldb.com/submit/919388 pastebin.com: https://pastebin.com/3VsEG3Rg ritm.ru: https://ritm.ru/contacts/

Credits

🔍 Xanik (VulDB User) VulDB CNA Team