CVE-2026-6280CWE-213

Improper Access Control in Nomysoft Informatics' Nomysem

Medium · published July 8, 2026

CVSS v3.1
6.5
EPSS
0%
Percentile
30.8
In the wild
Unconfirmed
What it is

Exposure of sensitive information due to incompatible policies vulnerability in NOMYSOFT Informatics Education and Consulting Inc. Nomysem allows Accessing Functionality Not Properly Constrained by ACLs.

This issue affects Nomysem: through 08072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

The record
Technical detail
CVSS v3.1
6.5 · MEDIUM
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS v4.0
Not supplied
EPSS
0.00377 · 30.8th percentile
Weakness
CWE-213 · Exposure of Sensitive Information Due to Incompatible Policies
Published
2026-07-08T08:45Z
EPSS history
Timeline
  • 08 JUL 08:45Z
    Improper Access Control in Nomysoft Informatics' Nomysem
    cvelistv5