CVE-2026-6280

MEDIUM

Improper Access Control in Nomysoft Informatics' Nomysem

Title source: cna
STIX 2.1

Description

Exposure of sensitive information due to incompatible policies vulnerability in NOMYSOFT Informatics Education and Consulting Inc. Nomysem allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Nomysem: through 08072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.

References (1)

Core 1
Core References

Scores

CVSS v3 6.5
EPSS 0.0023
EPSS Percentile 13.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-213
Status published
Products (1)
NOMYSOFT Informatics Education and Consulting Inc./Nomysem < 08072026
Published Jul 08, 2026
Tracked Since Jul 08, 2026