CVE-2026-103544 | datadrivenconstruction OpenConstructionERP up to 14.8.1 Al Provider Configuration ai_client.py wrong session (GHSA-wfpw-cv5v-64j5)

SecurityVulns

A vulnerability marked as critical has been reported in datadrivenconstruction OpenConstructionERP up to 14.8.1. The impacted element is an unknown function of the file backend/app/modules/ai/ai_client.py of the component Al Provider Configuration Handler. Performing a manipulation results in exposure of data element to wrong session.

This vulnerability was named CVE-2026-103544. The attack may be initiated remotely. In addition, an exploit is available.

It is suggested to upgrade the affected component.VulDB Recent EntriesRead More