Summary
A flaw in the authentication flow of a customer-facing portal allowed an attacker to reach authenticated functionality without valid credentials.
The vulnerability
Explain the root cause here — for example, a trust decision made on a client-controlled value, a missing server-side check, or a broken session-binding step. Describe how the request was crafted and what boundary it crossed.
Impact
With the bypass, an attacker could access account features intended only for authenticated users, which is why this rated critical.
Disclosure
Reported through the vendor’s responsible-disclosure channel and fixed. Replace the external link above with the official advisory.