CVE-2025-9986 Details
Description
Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability in Vadi Corporate Information Systems Ltd. Co. DIGIKENT allows Excavation. This issue affects DIGIKENT: through 13092025.
A vulnerability allowing the exposure of sensitive system information to an unauthorized control sphere has been identified in Vadi Corporate Information Systems Ltd. Co. DIGIKENT, affecting versions through 13092025. This vulnerability could potentially be exploited by cyber attackers to carry out their attacks.
Users are advised to upgrade to the version released on or after September 13, 2025.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 11, 2026CISA-ADP
Assessed Feb 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-26-0056 | [email protected] | |
| https://www.usom.gov.tr/bildirim/tr-26-0056 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-497 | Exposure of Sensitive System Information to an Unauthorized Control Sphere | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Vadi Corporate Information Systems Ltd. Co. DIGIKENT | <= 13092025 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 5, 2026 | CVE Modified | [email protected] |
| Feb 11, 2026 | New CVE Received | [email protected] |
Volerion