CVE-2022-26665

HIGH

Tyler Odyssey Portal <17.1.20 - Info Disclosure

Title source: llm
STIX 2.1

Description

An Insecure Direct Object Reference issue exists in the Tyler Odyssey Portal platform before 17.1.20. This may allow an external party to access sensitive case records.

References (5)

Core 5
Core References
Issue Tracking, Third Party Advisory, US Government Resource x_refsource_misc
https://www.calbar.ca.gov/About-Us/News/Data-Breach-Updates
Issue Tracking, Vendor Advisory x_refsource_misc
https://www.tylertech.com/dataharvest
Exploit, Technical Description, Third Party Advisory x_refsource_misc
https://www.judyrecords.com/what-happened-with-tyler-technologies
Third Party Advisory x_refsource_misc
https://www.judyrecords.com/info
Third Party Advisory x_refsource_misc
https://news.ycombinator.com/item?id=30502117

Scores

CVSS v3 7.5
EPSS 0.0049
EPSS Percentile 65.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-639
Status published
Products (1)
tylertech/odyssey_portal < 17.1.20
Published Apr 18, 2022
Tracked Since Feb 18, 2026