📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global vulnerability Enterprise Security, Software Development CRITICAL 55m Global vulnerability Software Development, Artificial Intelligence HIGH 1h Global apt Defense and Military CRITICAL 1h Global vulnerability Networking, Software, Infrastructure HIGH 1h Global phishing Information Technology HIGH 2h Global ransomware Multiple sectors CRITICAL 2h Global malware Multiple sectors CRITICAL 2h Global general Cybersecurity LOW 2h Global vulnerability Information Technology CRITICAL 2h Global vulnerability Technology/Software CRITICAL 3h Global vulnerability Enterprise Security, Software Development CRITICAL 55m Global vulnerability Software Development, Artificial Intelligence HIGH 1h Global apt Defense and Military CRITICAL 1h Global vulnerability Networking, Software, Infrastructure HIGH 1h Global phishing Information Technology HIGH 2h Global ransomware Multiple sectors CRITICAL 2h Global malware Multiple sectors CRITICAL 2h Global general Cybersecurity LOW 2h Global vulnerability Information Technology CRITICAL 2h Global vulnerability Technology/Software CRITICAL 3h Global vulnerability Enterprise Security, Software Development CRITICAL 55m Global vulnerability Software Development, Artificial Intelligence HIGH 1h Global apt Defense and Military CRITICAL 1h Global vulnerability Networking, Software, Infrastructure HIGH 1h Global phishing Information Technology HIGH 2h Global ransomware Multiple sectors CRITICAL 2h Global malware Multiple sectors CRITICAL 2h Global general Cybersecurity LOW 2h Global vulnerability Information Technology CRITICAL 2h Global vulnerability Technology/Software CRITICAL 3h
Vulnerabilities

CVE-2026-10285

Medium
CWE-266 — Weakness Type
Published: Jun 1, 2026  ·  Modified: Jun 4, 2026  ·  Source: NVD
CVSS v3
5.4
🔗 NVD Official
📄 Description (English)

A vulnerability has been found in DevaslanPHP project-management up to 2.0.0-beta1. Affected by this issue is the function KanbanScrumHelper::recordUpdated of the file app/Helpers/KanbanScrumHelper.php of the component Ticket Handler. The manipulation leads to improper authorization. The attack is possible to be carried out remotely. The project was informed of the problem early through an issue report but has not responded yet.

🤖 AI Executive Summary

CVE-2026-10285 is a medium-severity improper authorization vulnerability in DevaslanPHP project management software affecting versions up to 2.0.0-beta1. The vulnerability exists in the Ticket Handler component's KanbanScrumHelper class, allowing remote attackers to bypass authorization controls. With no patch currently available and the project unresponsive to disclosure, organizations using this software face elevated risk of unauthorized ticket/project access.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: Jun 2, 2026 00:34
🇸🇦 Saudi Arabia Impact Assessment
Saudi organizations using DevaslanPHP for project management—particularly in government agencies (NCA, CITC), financial institutions managing internal projects, and healthcare facilities using this platform—face unauthorized access risks to sensitive project tickets and data. The vulnerability could allow attackers to view, modify, or delete confidential project information without proper authorization. Government entities and critical infrastructure operators are at highest risk due to the sensitivity of project management data containing strategic information.
🏢 Affected Saudi Sectors
Government (NCA, CITC, Ministry entities) Banking and Financial Services Healthcare Energy and Utilities Telecommunications Education Manufacturing
⚖️ Saudi Risk Score (AI)
6.2
/ 10.0
🔧 Remediation Steps (English)
Immediate Actions:
1. Audit all DevaslanPHP installations to identify affected versions (up to 2.0.0-beta1)
2. Review access logs for the KanbanScrumHelper::recordUpdated function for suspicious activity
3. Restrict network access to DevaslanPHP instances using firewall rules and VPN requirements
4. Disable public-facing project management interfaces if not essential

Compensating Controls:
5. Implement Web Application Firewall (WAF) rules to monitor and block suspicious ticket handler requests
6. Apply principle of least privilege—ensure user roles have minimal necessary permissions
7. Enable comprehensive audit logging for all ticket modifications
8. Implement additional authentication layer (MFA) for project management access
9. Monitor for unauthorized ticket access patterns using SIEM

Patching Strategy:
10. Contact DevaslanPHP project maintainers directly for security patch timeline
11. Evaluate migration to alternative, actively maintained project management solutions
12. If upgrade available, test thoroughly in staging environment before production deployment

Detection Rules:
- Monitor for direct calls to app/Helpers/KanbanScrumHelper.php recordUpdated function
- Alert on ticket modifications by users without explicit authorization
- Track failed authorization attempts on ticket handler endpoints
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. تدقيق جميع تثبيتات DevaslanPHP لتحديد الإصدارات المتأثرة (حتى 2.0.0-beta1)
2. مراجعة سجلات الوصول لدالة KanbanScrumHelper::recordUpdated للنشاط المريب
3. تقييد الوصول إلى شبكة لمثيلات DevaslanPHP باستخدام قواعد جدار الحماية ومتطلبات VPN
4. تعطيل واجهات إدارة المشاريع المكشوفة للعامة إن لم تكن ضرورية

عناصر التحكم التعويضية:
5. تطبيق قواعد جدار تطبيقات الويب (WAF) لمراقبة وحظر طلبات معالج التذاكر المريبة
6. تطبيق مبدأ أقل امتياز - التأكد من أن أدوار المستخدمين لها أقل صلاحيات ضرورية
7. تفعيل تسجيل التدقيق الشامل لجميع تعديلات التذاكر
8. تطبيق طبقة مصادقة إضافية (MFA) لوصول إدارة المشاريع
9. مراقبة أنماط الوصول غير المصرح به للتذاكر باستخدام SIEM

استراتيجية التصحيح:
10. الاتصال المباشر بمشروع DevaslanPHP للحصول على جدول زمني لتصحيح الأمان
11. تقييم الهجرة إلى حلول إدارة مشاريع بديلة يتم صيانتها بنشاط
12. إذا كان التحديث متاحاً، اختبره بدقة في بيئة التجريب قبل النشر الإنتاجي

قواعد الكشف:
- مراقبة الاستدعاءات المباشرة لدالة recordUpdated في app/Helpers/KanbanScrumHelper.php
- تنبيه على تعديلات التذاكر من قبل مستخدمين بدون تفويض صريح
- تتبع محاولات التفويض الفاشلة على نقاط نهاية معالج التذاكر
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.9.1.1 - Access Control Policy (improper authorization violates access control principles) ECC 2024 A.9.2.1 - User Registration and De-registration (unauthorized access to user functions) ECC 2024 A.9.4.3 - Review of User Access Rights (requires monitoring of unauthorized access attempts) ECC 2024 A.12.4.1 - Event Logging (requires comprehensive audit trails for authorization failures)
🔵 SAMA CSF
SAMA CSF ID.AM-2 - Asset Management (identify and manage vulnerable software assets) SAMA CSF PR.AC-1 - Access Control Policy (improper authorization is direct violation) SAMA CSF PR.AC-4 - Access Rights Management (authorization bypass requires immediate remediation) SAMA CSF DE.CM-1 - Detection Processes (monitor for unauthorized access patterns)
🟡 ISO 27001:2022
ISO 27001:2022 A.5.15 - Access Control (authorization controls must be properly implemented) ISO 27001:2022 A.8.2 - User Access Management (improper authorization violates user access requirements) ISO 27001:2022 A.8.3 - User Responsibilities (users must not bypass authorization controls) ISO 27001:2022 A.8.33 - Information Security Event Logging (requires audit trails for authorization failures)
🟣 PCI DSS v4.0.1
PCI DSS 7.1 - Limit Access to System Components (authorization bypass violates access control) PCI DSS 7.2 - Ensure User Identity is Properly Identified (improper authorization affects identity verification) PCI DSS 10.2 - Implement Automated Audit Trails (requires logging of authorization failures)
📊 CVSS Score
5.4
/ 10.0 — Medium
📊 CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
Attack VectorN — None / Network
Attack ComplexityL — Low / Local
Privileges RequiredL — Low / Local
User InteractionN — None / Network
ScopeU — Unchanged
ConfidentialityN — None / Network
IntegrityL — Low / Local
AvailabilityL — Low / Local
📋 Quick Facts
Severity Medium
CVSS Score5.4
CWECWE-266
EPSS0.05%
Exploit No
Patch ✗ No
Published 2026-06-01
Source Feed nvd
🇸🇦 Saudi Risk Score
6.2
/ 10.0 — Saudi Risk
Priority: HIGH
🏷️ Tags
CWE-266
Share this CVE
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.