CVE-2026-39697 is a missing authorization vulnerability affecting HBSS Technologies' MAIO (The new AI GEO/SEO tool) through version 6.2.8, where incorrectly configured access control security levels allow unauthorized exploitation. This vulnerability enables attackers to bypass authentication mechanisms that should restrict access to sensitive functionality. The vulnerability carries a CVSS severity rating of 5.3 (Medium) with a network-based attack vector requiring no privileges or user interaction, indicating moderate risk. The primary impact is integrity compromise, as attackers could modify data or system states, though confidentiality and availability are not affected. There is currently no evidence of active exploitation in the wild, with an EPSS score of 0.000370 indicating minimal prevalence among real-world attacks. The vulnerability is not listed on the CISA Known Exploited Vulnerabilities catalog and shows no community activity on vulnerability tracking lists, suggesting limited awareness and exploit availability at this time.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| HBSS Technologies | MAIO – The New AI GEO / SEO Tool | >= 0, <= 6.2.8CNA affecteddefault unaffected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.