
PoC and enumeration script for CVE-2026-100903, a missing-authentication flaw in the GEO.RITM REST API that leaks object and driver data anonymously.
Description: A vulnerability in the POST /restapi/objects/obj-groups method of the GEO.RITM software REST API is related to a lack of authentication before executing the function.
Impact: Exploitation of this vulnerability could allow an attacker acting remotely without authentication, by passing an object identifier (objectId), to obtain the organizational and regional association of the object (division, region, operational status), and in some cases, the personal data of the responsible person (driver's last name and initials). When combined with the object enumeration method, this vulnerability allows for anonymous deanonymization of the entire fleet of monitored objects
CVSSv3.1 vector: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N (7.5 High)
CWE: CWE-306: Missing Authentication for Critical Function
Affected Component: RestApi endpoint: /restapi/objects/obj-groups
Vendor: ООО НПО Ритм
./ritm_park_enum.sh --tagret $HOST:PORT Also there is --help option