CVE-2026-6280
Exposure of sensitive information due to incompatible policies vulnerability in NOMYSOFT Informatics Education and Consulting Inc. Nomysem allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Nomysem: through 08072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.5
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
- EPSS probability
- 0.38%
- CWE
- CWE-213
- Published
- 2026-07-08
- Last modified
- 2026-07-08
Affected products
- NOMYSOFT Informatics Education and Consulting Inc. Nomysem
Weakness type
Related vulnerabilities
- CVE-2026-55425 — Graylog: System Catalog titles endpoint can be used to retrieve values of protected database fields
- CVE-2026-56538 — HCL Connections is vulnerable to information disclosure
- CVE-2025-52603 — HCL Connections is vulnerable to information disclosure
- CVE-2025-54831 — Apache Airflow: Connection sensitive details exposed to users with READ permissions
- CVE-2024-49827 — IBM Concert Software information disclosure
- CVE-2025-4976 — Exposure of Sensitive Information Due to Incompatible Policies in GitLab
- CVE-2025-32791 — Permission policy information leakage in Backstage permission system
- CVE-2025-24316 — Dario Health USB-C Blood Glucose Monitoring System Starter Kit Android Application Exposure of Sensitive Information Due to Incompatible Policies