MeWare Software Development Inc.'s PDKS platform was disclosed with two high-severity vulnerabilities affecting versions from V16.20200313 before VMYR_3.5.2025117. CVE-2026-7399 is an insecure direct object reference (IDOR) issue mapped to CWE-639 that allows authorization bypass through a user-controlled key, enabling attackers with low privileges to abuse access rights and expose or alter sensitive data. The flaw carries a CVSS v3.1 vector of AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N, indicating network-reachable exploitation with low attack complexity and high impact on confidentiality and integrity.
A second flaw, CVE-2026-7402, affects the same product range and stems from improper rate limiting, tracked as CWE-799. The vulnerability allows flooding attacks against PDKS and is rated with the CVSS v3.1 vector AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H, reflecting high impact on integrity and availability. Both issues were referenced in advisories published through USOM, pointing organizations using vulnerable PDKS releases to update to a fixed version at or beyond VMYR_3.5.2025117.

See affected versions and whether adversaries are exploiting it.
2 events from the most recent confirmed update back to the earliest known activity.
Two high-severity vulnerabilities in MeWare Software Development Inc. PDKS were publicly recorded: CVE-2026-7402 for improper rate limiting that could allow flooding, and CVE-2026-7399 for an authorization bypass via a user-controlled key. Both entries reference USOM advisories and affect PDKS versions from V16.20200313 before VMYR_3.5.2025117.
A vulnerability report for CVE-2026-7399 was received by iletisim@usom.gov.tr, describing an insecure direct object reference/authorization bypass issue in MeWare Software Development Inc. PDKS. The flaw affects versions from V16.20200313 before VMYR_3.5.2025117 and could enable privilege abuse.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.