CVE-2026-100903 Details
Description
A vulnerability was identified in ООО НПО Ритм GEOritm up to 2.45.1. This affects an unknown part of the file /restapi/objects/obj-groups of the component REST API. Such manipulation of the argument objectId leads to missing authentication. The attack can be launched remotely. The exploit is publicly available and might be used. Upgrading to version 2.46 is able to mitigate this issue. It is advisable to upgrade the affected component. The vendor confirms: "In August 2026, NPO Ritm received an official vulnerability notification from the Russian Federal Service for Technical and Export Control (FSTEC Russia). The vulnerability was registered under identifier BDU:2026-11235. Following our internal investigation, we confirmed the vulnerability and implemented the necessary security fixes. The vulnerability has been fixed on our hosted GEO.RITM server at geo.ritm.ru. The fix has also been included in GEO.RITM version 2.46, which is already being distributed to our customers."
A vulnerability exists in GEOritm versions through 2.45.1, specifically within the REST API endpoint '/restapi/objects/obj-groups'. The issue arises from a lack of authentication, allowing remote exploitation by manipulating the 'objectId' argument. This vulnerability enables unauthorized access to organizational and regional data of monitored objects, including personal information of responsible individuals, such as driver's names and initials. When used with the object enumeration method, it could lead to anonymous deanonymization of the entire fleet of monitored objects.
Users are advised to upgrade to GEOritm version 2.46, which addresses this vulnerability.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 28, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/4ybrick/CVE-2026-100903 | [email protected] | ExploitTechnical Description |
| https://pastebin.com/3VsEG3Rg | [email protected] | ExploitPartial Content |
| https://ritm.ru/contacts/ | [email protected] | Vendor |
| https://vuldb.com/cve/CVE-2026-100903 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/919388 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/410853 | [email protected] | BundlePermission Required |
| https://vuldb.com/vuln/410853/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-287 | Improper Authentication | [email protected] |
| CWE-306 | Missing Authentication for Critical Function | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| ООО НПО Ритм GEOritm | <= 2.45.1 (semver) |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 28, 2026 | CVE Modified | [email protected] |
| Sep 28, 2026 | New CVE Received | [email protected] |
Volerion