Officially credited finder
$ verify --cve CVE-2026-19441
CVE-2026-19441
Unauthenticated API Allows Analytics Data Manipulation in IKAS Technology's Rush
Missing authentication for a critical API function could allow an unauthenticated remote attacker to falsify analytics source data.
Public record summary
- Researcher credit
- Basri Akkaya — finder
- Vendor
- IKAS Technology Inc.
- Affected product
- Rush
- Severity
- MEDIUM · CVSS 5.3
- Published
- CVE
- CVE-2026-19441
Technical classification
CWE-306Missing Authentication for Critical FunctionMITRE CWE definition (opens in a new tab)CAPEC-194Fake the Source of DataMITRE CAPEC definition (opens in a new tab)
CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Authoritative sources
The facts and researcher credit on this page are based on the published CVE record and the government advisory.
Responsible disclosure note
This page summarizes public information only. It does not publish private report material, credentials, or undisclosed exploitation details.