Kaleris develops yard management solutions for logistics and intermodal operations, a specialized domain where the vendor's exposure centers on authentication and authorization weakness classes including alternate-path authentication bypass, user-controlled key authorization bypass, and improper access control. These recurring patterns reflect the access-control demands of operational software managing physical asset movement and yard operations. Current severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Kaleris over time
Signals from CVEs in this vendor scope (2 CVEs).
2 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-31151CRITICAL An issue in the login mechanism of Kaleris YMS v7.2.2.1 allows attackers to bypass login verification to access the application 's resources. | Apr 6, 2026 | 9.8 | 30 | NO | NO |
CVE-2026-31150MEDIUM Incorrect access control in Kaleris YMS v7.2.2.1 allows authenticated attackers with only the shipping/receiving role to view the truck's dashboard resources. | Apr 6, 2026 | 4.3 | 18 | NO | NO |
Signals from CVEs in this vendor scope (2 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Kaleris.
Media articles that mention a CVE ID that affects a product developed by Kaleris — matched by CVE ID, not by vendor name.