Officially credited finder

$ verify --cve CVE-2026-19441

CVE-2026-19441

Unauthenticated API Allows Analytics Data Manipulation in IKAS Technology's Rush

Missing authentication for a critical API function could allow an unauthenticated remote attacker to falsify analytics source data.

Public record summary

Researcher credit
Basri Akkaya — finder
Vendor
IKAS Technology Inc.
Affected product
Rush
Severity
MEDIUM · CVSS 5.3
Published
CVE
CVE-2026-19441

Technical classification

CVSS vectorCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Authoritative sources

The facts and researcher credit on this page are based on the published CVE record and the government advisory.

Responsible disclosure note

This page summarizes public information only. It does not publish private report material, credentials, or undisclosed exploitation details.

View all security research