CWE-259
AllowedUse of Hard-coded Password
Abstraction: Variant · Status: Draft
The product contains a hard-coded password, which it uses for its own inbound authentication or for outbound communication to external components.
353 vulnerabilities reference this CWE, most recent first.
CVE-2026-101052 (GCVE-0-2026-101052)
Vulnerability from cvelistv5 – Published: 2026-09-28 11:15 – Updated: 2026-09-28 12:20| URL | Tags |
|---|---|
| https://vuldb.com/vuln/410910 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/410910/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-101052 | third-party-advisory |
| https://vuldb.com/submit/927328 | third-party-advisory |
| https://github.com/DReazer/CV3/blob/main/refly/Ha… | exploit |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-101052",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-28T11:26:13.118604Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T12:20:23.582Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:refly-ai:refly:*:*:*:*:*:*:*:*"
],
"modules": [
"JWT Token Handler"
],
"product": "refly",
"vendor": "refly-ai",
"versions": [
{
"status": "affected",
"version": "1.0"
},
{
"status": "affected",
"version": "1.1.0"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Snkn0w (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A security vulnerability has been detected in refly-ai refly up to 1.1.0. This issue affects some unknown processing of the file apps/api/src/modules/config/app.config.ts of the component JWT Token Handler. The manipulation with the input test leads to hard-coded credentials. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 7.5,
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:C",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-798",
"description": "Hard-coded Credentials",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-259",
"description": "Use of Hard-coded Password",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-28T11:15:06.560Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-410910 | refly-ai refly JWT Token app.config.ts hard-coded credentials",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/410910"
},
{
"name": "VDB-410910 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/410910/cti"
},
{
"name": "CVE-2026-101052 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-101052"
},
{
"name": "Submit #927328 | Refly AI refly \u003c=1.1.0 Hard-coded Credentials",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/927328"
},
{
"tags": [
"exploit"
],
"url": "https://github.com/DReazer/CV3/blob/main/refly/Hard-coded.md"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-27T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-27T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-27T18:27:41.000Z",
"value": "VulDB entry last update"
}
],
"title": "refly-ai refly JWT Token app.config.ts hard-coded credentials",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-101052",
"datePublished": "2026-09-28T11:15:06.560Z",
"dateReserved": "2026-09-27T16:22:27.168Z",
"dateUpdated": "2026-09-28T12:20:23.582Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-97877 (GCVE-0-2026-97877)
Vulnerability from cvelistv5 – Published: 2026-09-25 16:15 – Updated: 2026-09-25 17:21| URL | Tags |
|---|---|
| https://vuldb.com/vuln/409898 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/409898/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-97877 | third-party-advisory |
| https://vuldb.com/submit/913575 | third-party-advisory |
| https://github.com/ArrestX/startraining-advisorie… | exploit |
| Vendor | Product | Version | |
|---|---|---|---|
| zhistaredu | StarTraining |
Affected:
3.8.0
Affected: 3.8.1 cpe:2.3:a:zhistaredu:startraining:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-97877",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-25T17:21:24.486127Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-25T17:21:34.774Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:zhistaredu:startraining:*:*:*:*:*:*:*:*"
],
"modules": [
"JWT Token Handler"
],
"product": "StarTraining",
"vendor": "zhistaredu",
"versions": [
{
"status": "affected",
"version": "3.8.0"
},
{
"status": "affected",
"version": "3.8.1"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "Vseen (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was determined in zhistaredu StarTraining up to 3.8.1. This issue affects the function UserLoginService.createToken of the file application.yml of the component JWT Token Handler. This manipulation of the argument user_id/company_id causes use of hard-coded password. The attack is possible to be carried out remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:C",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 7.5,
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:C",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-259",
"description": "Use of Hard-coded Password",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-255",
"description": "Credentials Management",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-25T16:15:10.564Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-409898 | zhistaredu StarTraining JWT Token application.yml UserLoginService.createToken hard-coded password",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/409898"
},
{
"name": "VDB-409898 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/409898/cti"
},
{
"name": "CVE-2026-97877 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-97877"
},
{
"name": "Submit #913575 | zhistaredu 3.8.1 Use of Hard-coded Password",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/913575"
},
{
"tags": [
"exploit"
],
"url": "https://github.com/ArrestX/startraining-advisories/blob/main/advisories/ST-VULN-001-jwt-hardcoded-secret-forge.md"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-25T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-25T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-25T11:01:59.000Z",
"value": "VulDB entry last update"
}
],
"title": "zhistaredu StarTraining JWT Token application.yml UserLoginService.createToken hard-coded password",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-97877",
"datePublished": "2026-09-25T16:15:10.564Z",
"dateReserved": "2026-09-25T08:56:43.368Z",
"dateUpdated": "2026-09-25T17:21:34.774Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-96548 (GCVE-0-2026-96548)
Vulnerability from cvelistv5 – Published: 2026-09-23 18:30 – Updated: 2026-09-23 18:44| URL | Tags |
|---|---|
| https://vuldb.com/vuln/408950 | vdb-entry |
| https://vuldb.com/vuln/408950/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-96548 | third-party-advisory |
| https://vuldb.com/submit/907904 | third-party-advisory |
| https://github.com/sfturing/hosp_order/issues/119 | exploitissue-tracking |
| https://github.com/sfturing/hosp_order/ | product |
| Vendor | Product | Version | |
|---|---|---|---|
| sfturing | hosp_order |
Affected:
627f426331da8086ce8fff2017d65b1ddef384f8
cpe:2.3:a:sfturing:hosp_order:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-96548",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-23T18:43:56.129603Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-23T18:44:03.113Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:sfturing:hosp_order:*:*:*:*:*:*:*:*"
],
"product": "hosp_order",
"vendor": "sfturing",
"versions": [
{
"status": "affected",
"version": "627f426331da8086ce8fff2017d65b1ddef384f8"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "zbzz (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A flaw has been found in sfturing hosp_order up to 627f426331da8086ce8fff2017d65b1ddef384f8. This affects an unknown part of the file ssm_pro/src/main/resources/jdbc.properties. This manipulation causes hard-coded credentials. It is possible to initiate the attack remotely. The attack\u0027s complexity is rated as high. It is indicated that the exploitability is difficult. The exploit has been published and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.3,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 5.6,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 5.6,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 5.1,
"vectorString": "AV:N/AC:H/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-798",
"description": "Hard-coded Credentials",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-259",
"description": "Use of Hard-coded Password",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-23T18:30:13.119Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-408950 | sfturing hosp_order jdbc.properties hard-coded credentials",
"tags": [
"vdb-entry"
],
"url": "https://vuldb.com/vuln/408950"
},
{
"name": "VDB-408950 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/408950/cti"
},
{
"name": "CVE-2026-96548 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-96548"
},
{
"name": "Submit #907904 | sfturing hosp_order 627f426331da8086ce8fff2017d65b1ddef384f8 Hard-coded Credentials",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/907904"
},
{
"tags": [
"exploit",
"issue-tracking"
],
"url": "https://github.com/sfturing/hosp_order/issues/119"
},
{
"tags": [
"product"
],
"url": "https://github.com/sfturing/hosp_order/"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-23T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-23T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-23T14:53:13.000Z",
"value": "VulDB entry last update"
}
],
"title": "sfturing hosp_order jdbc.properties hard-coded credentials",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-96548",
"datePublished": "2026-09-23T18:30:13.119Z",
"dateReserved": "2026-09-23T12:47:52.852Z",
"dateUpdated": "2026-09-23T18:44:03.113Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-93970 (GCVE-0-2026-93970)
Vulnerability from cvelistv5 – Published: 2026-09-20 07:15 – Updated: 2026-09-23 18:17 X_Open Source| URL | Tags |
|---|---|
| https://vuldb.com/vuln/407929 | vdb-entry |
| https://vuldb.com/vuln/407929/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-93970 | third-party-advisory |
| https://vuldb.com/submit/944385 | third-party-advisory |
| https://github.com/aiyiyi121/sxdevops/issues/16 | issue-tracking |
| https://github.com/aiyiyi121/sxdevops/commit/2b4b… | patch |
| https://github.com/aiyiyi121/sxdevops/ | product |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-93970",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-23T18:16:53.303948Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-23T18:17:06.871Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:aiyiyi121:sxdevops:*:*:*:*:*:*:*:*"
],
"modules": [
"Settings Handler"
],
"product": "SxDevOps",
"vendor": "aiyiyi121",
"versions": [
{
"status": "affected",
"version": "1.0"
},
{
"status": "affected",
"version": "1.1"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "_lxf (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A security flaw has been discovered in aiyiyi121 SxDevOps 1.0/1.1. This issue affects some unknown processing of the file backend/sxdevops/settings.py of the component Settings Handler. The manipulation results in hard-coded credentials. The attack may be performed from remote. The patch is identified as 2b4bf8585c3e731e7a8af30801ea46680bc783f9. Applying a patch is advised to resolve this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 7.5,
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:ND/RL:OF/RC:C",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-798",
"description": "Hard-coded Credentials",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-259",
"description": "Use of Hard-coded Password",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-20T07:15:10.686Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-407929 | aiyiyi121 SxDevOps Settings settings.py hard-coded credentials",
"tags": [
"vdb-entry"
],
"url": "https://vuldb.com/vuln/407929"
},
{
"name": "VDB-407929 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/407929/cti"
},
{
"name": "CVE-2026-93970 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-93970"
},
{
"name": "Submit #944385 | aiyiyi121 SxDevOps 1.1 Use of Hard-coded Cryptographic Key",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/944385"
},
{
"tags": [
"issue-tracking"
],
"url": "https://github.com/aiyiyi121/sxdevops/issues/16"
},
{
"tags": [
"patch"
],
"url": "https://github.com/aiyiyi121/sxdevops/commit/2b4bf8585c3e731e7a8af30801ea46680bc783f9"
},
{
"tags": [
"product"
],
"url": "https://github.com/aiyiyi121/sxdevops/"
}
],
"tags": [
"x_open-source"
],
"timeline": [
{
"lang": "en",
"time": "2026-09-19T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-19T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-19T12:20:30.000Z",
"value": "VulDB entry last update"
}
],
"title": "aiyiyi121 SxDevOps Settings settings.py hard-coded credentials",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-93970",
"datePublished": "2026-09-20T07:15:10.686Z",
"dateReserved": "2026-09-19T10:15:01.679Z",
"dateUpdated": "2026-09-23T18:17:06.871Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-93969 (GCVE-0-2026-93969)
Vulnerability from cvelistv5 – Published: 2026-09-20 06:45 – Updated: 2026-09-22 15:43 X_Open Source| URL | Tags |
|---|---|
| https://vuldb.com/vuln/407928 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/407928/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-93969 | third-party-advisory |
| https://vuldb.com/submit/944384 | third-party-advisory |
| https://github.com/aiyiyi121/sxdevops/issues/16 | issue-tracking |
| https://github.com/aiyiyi121/sxdevops/commit/2b4b… | patch |
| https://github.com/aiyiyi121/sxdevops/ | product |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-93969",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-22T14:57:12.266579Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-22T15:43:36.353Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:aiyiyi121:sxdevops:*:*:*:*:*:*:*:*"
],
"product": "SxDevOps",
"vendor": "aiyiyi121",
"versions": [
{
"status": "affected",
"version": "1.0"
},
{
"status": "affected",
"version": "1.1"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "_lxf (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was identified in aiyiyi121 SxDevOps 1.0/1.1. This vulnerability affects the function ensure_default_superuser of the file rbac/services.py. The manipulation leads to hard-coded credentials. The attack is possible to be carried out remotely. The identifier of the patch is 2b4bf8585c3e731e7a8af30801ea46680bc783f9. It is recommended to apply a patch to fix this issue. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:X/RL:O/RC:C",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 7.5,
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:ND/RL:OF/RC:C",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-798",
"description": "Hard-coded Credentials",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-259",
"description": "Use of Hard-coded Password",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-20T06:45:09.655Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-407928 | aiyiyi121 SxDevOps services.py ensure_default_superuser hard-coded credentials",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/407928"
},
{
"name": "VDB-407928 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/407928/cti"
},
{
"name": "CVE-2026-93969 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-93969"
},
{
"name": "Submit #944384 | aiyiyi121 SxDevOps 1.1 Hard-coded Credentials",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/944384"
},
{
"tags": [
"issue-tracking"
],
"url": "https://github.com/aiyiyi121/sxdevops/issues/16"
},
{
"tags": [
"patch"
],
"url": "https://github.com/aiyiyi121/sxdevops/commit/2b4bf8585c3e731e7a8af30801ea46680bc783f9"
},
{
"tags": [
"product"
],
"url": "https://github.com/aiyiyi121/sxdevops/"
}
],
"tags": [
"x_open-source"
],
"timeline": [
{
"lang": "en",
"time": "2026-09-19T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-19T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-19T12:20:26.000Z",
"value": "VulDB entry last update"
}
],
"title": "aiyiyi121 SxDevOps services.py ensure_default_superuser hard-coded credentials",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-93969",
"datePublished": "2026-09-20T06:45:09.655Z",
"dateReserved": "2026-09-19T10:14:58.229Z",
"dateUpdated": "2026-09-22T15:43:36.353Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-90509 (GCVE-0-2026-90509)
Vulnerability from cvelistv5 – Published: 2026-09-13 10:00 – Updated: 2026-09-20 00:35| URL | Tags |
|---|---|
| https://vuldb.com/vuln/403097 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/403097/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-90509 | third-party-advisory |
| https://vuldb.com/submit/911864 | third-party-advisory |
| https://github.com/dromara/orion-visor/issues/170 | issue-tracking |
| https://github.com/sumo166/CVE-apply/blob/main/dr… | exploit |
| https://github.com/dromara/orion-visor/ | product |
| Vendor | Product | Version | |
|---|---|---|---|
| dromara | orion-visor |
Affected:
2.5.0
Affected: 2.5.1 Affected: 2.5.2 Affected: 2.5.3 Affected: 2.5.4 Affected: 2.5.5 Affected: 2.5.6 Affected: 2.5.7 cpe:2.3:a:dromara:orion-visor:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-90509",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-20T00:10:34.891101Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-20T00:35:31.889Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:dromara:orion-visor:*:*:*:*:*:*:*:*"
],
"product": "orion-visor",
"vendor": "dromara",
"versions": [
{
"status": "affected",
"version": "2.5.0"
},
{
"status": "affected",
"version": "2.5.1"
},
{
"status": "affected",
"version": "2.5.2"
},
{
"status": "affected",
"version": "2.5.3"
},
{
"status": "affected",
"version": "2.5.4"
},
{
"status": "affected",
"version": "2.5.5"
},
{
"status": "affected",
"version": "2.5.6"
},
{
"status": "affected",
"version": "2.5.7"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "summmm (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A weakness has been identified in dromara orion-visor up to 2.5.7. Affected by this issue is the function ExposeApiAspect.beforeExposeApi of the file ExposeApiAspect.java. Executing a manipulation can lead to hard-coded credentials. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 7.5,
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-798",
"description": "Hard-coded Credentials",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-259",
"description": "Use of Hard-coded Password",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-13T10:00:08.909Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-403097 | dromara orion-visor ExposeApiAspect.java ExposeApiAspect.beforeExposeApi hard-coded credentials",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/403097"
},
{
"name": "VDB-403097 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/403097/cti"
},
{
"name": "CVE-2026-90509 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-90509"
},
{
"name": "Submit #911864 | dromara orion-visor v2.5.7 Default Token",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/911864"
},
{
"tags": [
"issue-tracking"
],
"url": "https://github.com/dromara/orion-visor/issues/170"
},
{
"tags": [
"exploit"
],
"url": "https://github.com/sumo166/CVE-apply/blob/main/dromara-orion-visor/ExposeApi%20Hardcoded%20Default%20Token%20Authentication%20Bypass%20(CWE-798)_en.md"
},
{
"tags": [
"product"
],
"url": "https://github.com/dromara/orion-visor/"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-12T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-12T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-12T11:03:37.000Z",
"value": "VulDB entry last update"
}
],
"title": "dromara orion-visor ExposeApiAspect.java ExposeApiAspect.beforeExposeApi hard-coded credentials",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-90509",
"datePublished": "2026-09-13T10:00:08.909Z",
"dateReserved": "2026-09-12T08:58:28.519Z",
"dateUpdated": "2026-09-20T00:35:31.889Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-86673 (GCVE-0-2026-86673)
Vulnerability from cvelistv5 – Published: 2026-09-08 18:00 – Updated: 2026-09-08 18:11| URL | Tags |
|---|---|
| https://vuldb.com/vuln/399764 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/399764/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-86673 | third-party-advisory |
| https://vuldb.com/submit/908932 | third-party-advisory |
| https://github.com/ningzichun/student-management-… | exploitissue-tracking |
| Vendor | Product | Version | |
|---|---|---|---|
| ningzichun | Student Management System |
Affected:
98760f5711cf6dc8b4adca53a9e207ca49b02ebf
cpe:2.3:a:ningzichun:student_management_system:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-86673",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-08T18:11:35.507298Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-08T18:11:42.177Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:ningzichun:student_management_system:*:*:*:*:*:*:*:*"
],
"modules": [
"Database Connection"
],
"product": "Student Management System",
"vendor": "ningzichun",
"versions": [
{
"status": "affected",
"version": "98760f5711cf6dc8b4adca53a9e207ca49b02ebf"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "ctrl (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was determined in ningzichun Student Management System up to 98760f5711cf6dc8b4adca53a9e207ca49b02ebf. Affected by this issue is the function mysqli_connect of the file config/database.php of the component Database Connection. This manipulation causes hard-coded credentials. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. This product uses a rolling release model to deliver continuous updates. As a result, specific version information for affected or updated releases is not available. The project was informed of the problem early through an issue report but has not responded yet."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 7.5,
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:C",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-798",
"description": "Hard-coded Credentials",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-259",
"description": "Use of Hard-coded Password",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-08T18:00:08.510Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-399764 | ningzichun Student Management System Database Connection database.php mysqli_connect hard-coded credentials",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/399764"
},
{
"name": "VDB-399764 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/399764/cti"
},
{
"name": "CVE-2026-86673 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-86673"
},
{
"name": "Submit #908932 | ningzichun student-management-system 98760f5711cf6dc8b4adca53a9e207ca49b02ebf Hard-coded Credentials",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/908932"
},
{
"tags": [
"exploit",
"issue-tracking"
],
"url": "https://github.com/ningzichun/student-management-system/issues/15"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-08T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-08T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-08T11:41:33.000Z",
"value": "VulDB entry last update"
}
],
"title": "ningzichun Student Management System Database Connection database.php mysqli_connect hard-coded credentials",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-86673",
"datePublished": "2026-09-08T18:00:08.510Z",
"dateReserved": "2026-09-08T09:36:15.259Z",
"dateUpdated": "2026-09-08T18:11:42.177Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-86276 (GCVE-0-2026-86276)
Vulnerability from cvelistv5 – Published: 2026-09-07 05:45 – Updated: 2026-09-09 14:16 X_Freeware| URL | Tags |
|---|---|
| https://vuldb.com/vuln/399437 | vdb-entry |
| https://vuldb.com/vuln/399437/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-86276 | third-party-advisory |
| https://vuldb.com/submit/904873 | third-party-advisory |
| https://github.com/hackliu/Vulnerability-Reports/… | exploit |
| https://www.sourcecodester.com/ | product |
| Vendor | Product | Version | |
|---|---|---|---|
| SourceCodester | Syllabus-Aligned Learning Management & Examination System |
Affected:
1.0
cpe:2.3:a:sourcecodester:syllabus-aligned_learning_management_examination_system:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-86276",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-09T14:15:33.974401Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-09T14:16:27.113Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:sourcecodester:syllabus-aligned_learning_management_examination_system:*:*:*:*:*:*:*:*"
],
"product": "Syllabus-Aligned Learning Management \u0026 Examination System",
"vendor": "SourceCodester",
"versions": [
{
"status": "affected",
"version": "1.0"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "BI1IHA (VulDB User)"
}
],
"descriptions": [
{
"lang": "en",
"value": "A flaw has been found in SourceCodester Syllabus-Aligned Learning Management \u0026 Examination System 1.0. This issue affects some unknown processing of the file db.php. Executing a manipulation can lead to hard-coded credentials. The attack can be executed remotely. The exploit has been published and may be used."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 7.5,
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-798",
"description": "Hard-coded Credentials",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-259",
"description": "Use of Hard-coded Password",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-07T05:45:09.115Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-399437 | SourceCodester Syllabus-Aligned Learning Management \u0026 Examination System db.php hard-coded credentials",
"tags": [
"vdb-entry"
],
"url": "https://vuldb.com/vuln/399437"
},
{
"name": "VDB-399437 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/399437/cti"
},
{
"name": "CVE-2026-86276 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-86276"
},
{
"name": "Submit #904873 | SourceCodester Syllabus-Aligned Learning Management \u0026 Examination System 1.0 Hard-coded Credentials",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/904873"
},
{
"tags": [
"exploit"
],
"url": "https://github.com/hackliu/Vulnerability-Reports/blob/master/Syllabus%20Aligned%20Learning%20Management%20Examination%20System/VULN-03-SQL-Injection-Hardcoded-Credentials.md"
},
{
"tags": [
"product"
],
"url": "https://www.sourcecodester.com/"
}
],
"tags": [
"x_freeware"
],
"timeline": [
{
"lang": "en",
"time": "2026-09-06T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-06T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-06T15:39:07.000Z",
"value": "VulDB entry last update"
}
],
"title": "SourceCodester Syllabus-Aligned Learning Management \u0026 Examination System db.php hard-coded credentials",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-86276",
"datePublished": "2026-09-07T05:45:09.115Z",
"dateReserved": "2026-09-06T13:33:35.535Z",
"dateUpdated": "2026-09-09T14:16:27.113Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-86150 (GCVE-0-2026-86150)
Vulnerability from cvelistv5 – Published: 2026-09-05 23:00 – Updated: 2026-09-08 13:23| URL | Tags |
|---|---|
| https://vuldb.com/vuln/399273 | vdb-entrytechnical-description |
| https://vuldb.com/vuln/399273/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-86150 | third-party-advisory |
| https://vuldb.com/submit/895351 | third-party-advisory |
| https://www.tenda.com.cn/ | product |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-86150",
"options": [
{
"Exploitation": "none"
},
{
"Automatable": "no"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-09-08T13:23:34.690657Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-09-08T13:23:49.631Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:o:tenda:cp3_firmware:*:*:*:*:*:*:*:*"
],
"product": "CP3",
"vendor": "Tenda",
"versions": [
{
"status": "affected",
"version": "27.5.57.101"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "FengZi (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB Vulnerability Moderation Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A security vulnerability has been detected in Tenda CP3 27.5.57.101. Impacted is an unknown function of the file custom-x/softap/hostapd. Such manipulation of the argument wpa_passphrase leads to hard-coded credentials. The attack can be launched remotely. The exploit has been disclosed publicly and may be used."
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 5.1,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:N/VA:N/SC:L/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 4.1,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N/E:P/RL:X/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 4.1,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:C/C:L/I:N/A:N/E:P/RL:X/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 3.3,
"vectorString": "AV:N/AC:L/Au:M/C:P/I:N/A:N/E:POC/RL:ND/RC:UR",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-798",
"description": "Hard-coded Credentials",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-259",
"description": "Use of Hard-coded Password",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-09-05T23:00:12.424Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-399273 | Tenda CP3 hostapd hard-coded credentials",
"tags": [
"vdb-entry",
"technical-description"
],
"url": "https://vuldb.com/vuln/399273"
},
{
"name": "VDB-399273 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/399273/cti"
},
{
"name": "CVE-2026-86150 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-86150"
},
{
"name": "Submit #895351 | Tenda CP3 V3.2 V27.5.57.101 Use of Hard-coded Password",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/895351"
},
{
"tags": [
"product"
],
"url": "https://www.tenda.com.cn/"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-09-05T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-09-05T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-09-05T09:45:48.000Z",
"value": "VulDB entry last update"
}
],
"title": "Tenda CP3 hostapd hard-coded credentials",
"x_generator": [
"VulDB PVTS v202609"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-86150",
"datePublished": "2026-09-05T23:00:12.424Z",
"dateReserved": "2026-09-05T07:40:23.987Z",
"dateUpdated": "2026-09-08T13:23:49.631Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
CVE-2026-82808 (GCVE-0-2026-82808)
Vulnerability from cvelistv5 – Published: 2026-08-31 16:15 – Updated: 2026-08-31 19:02| URL | Tags |
|---|---|
| https://vuldb.com/vuln/397227 | vdb-entry |
| https://vuldb.com/vuln/397227/cti | signaturepermissions-required |
| https://vuldb.com/cve/CVE-2026-82808 | third-party-advisory |
| https://vuldb.com/submit/874121 | third-party-advisory |
| https://github.com/xryj920/chrome_extensions/blob… | exploit |
| Vendor | Product | Version | |
|---|---|---|---|
| Inbox Foundry | ActiveInbox Extension |
Affected:
7.10.0
Affected: 7.10.1 Affected: 7.10.2 Affected: 7.10.3 Affected: 7.10.4 Affected: 7.10.5 Affected: 7.10.6 Affected: 7.10.7 Affected: 7.10.8 Affected: 7.10.9 Affected: 7.10.10 Affected: 7.10.11 Affected: 7.10.12 Affected: 7.10.13 Affected: 7.10.14 Affected: 7.10.15 Affected: 7.10.16 Affected: 7.10.17 Affected: 7.10.18 Affected: 7.10.19 Affected: 7.10.20 Affected: 7.10.21 Affected: 7.10.22 Affected: 7.10.23 Affected: 7.10.24 cpe:2.3:a:inbox_foundry:activeinbox_extension:*:*:*:*:*:*:*:* |
{
"containers": {
"adp": [
{
"metrics": [
{
"other": {
"content": {
"id": "CVE-2026-82808",
"options": [
{
"Exploitation": "poc"
},
{
"Automatable": "yes"
},
{
"Technical Impact": "partial"
}
],
"role": "CISA Coordinator",
"timestamp": "2026-08-31T19:02:32.607781Z",
"version": "2.0.3"
},
"type": "ssvc"
}
}
],
"providerMetadata": {
"dateUpdated": "2026-08-31T19:02:39.743Z",
"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"shortName": "CISA-ADP"
},
"references": [
{
"tags": [
"exploit"
],
"url": "https://vuldb.com/submit/874121"
}
],
"title": "CISA ADP Vulnrichment"
}
],
"cna": {
"affected": [
{
"cpes": [
"cpe:2.3:a:inbox_foundry:activeinbox_extension:*:*:*:*:*:*:*:*"
],
"modules": [
"Google OAuth Client Secret"
],
"product": "ActiveInbox Extension",
"vendor": "Inbox Foundry",
"versions": [
{
"status": "affected",
"version": "7.10.0"
},
{
"status": "affected",
"version": "7.10.1"
},
{
"status": "affected",
"version": "7.10.2"
},
{
"status": "affected",
"version": "7.10.3"
},
{
"status": "affected",
"version": "7.10.4"
},
{
"status": "affected",
"version": "7.10.5"
},
{
"status": "affected",
"version": "7.10.6"
},
{
"status": "affected",
"version": "7.10.7"
},
{
"status": "affected",
"version": "7.10.8"
},
{
"status": "affected",
"version": "7.10.9"
},
{
"status": "affected",
"version": "7.10.10"
},
{
"status": "affected",
"version": "7.10.11"
},
{
"status": "affected",
"version": "7.10.12"
},
{
"status": "affected",
"version": "7.10.13"
},
{
"status": "affected",
"version": "7.10.14"
},
{
"status": "affected",
"version": "7.10.15"
},
{
"status": "affected",
"version": "7.10.16"
},
{
"status": "affected",
"version": "7.10.17"
},
{
"status": "affected",
"version": "7.10.18"
},
{
"status": "affected",
"version": "7.10.19"
},
{
"status": "affected",
"version": "7.10.20"
},
{
"status": "affected",
"version": "7.10.21"
},
{
"status": "affected",
"version": "7.10.22"
},
{
"status": "affected",
"version": "7.10.23"
},
{
"status": "affected",
"version": "7.10.24"
}
]
}
],
"credits": [
{
"lang": "en",
"type": "reporter",
"value": "DRXYJ (VulDB User)"
},
{
"lang": "en",
"type": "coordinator",
"value": "VulDB CNA Team"
}
],
"descriptions": [
{
"lang": "en",
"value": "A vulnerability was identified in Inbox Foundry ActiveInbox Extension up to 7.10.24 on Chrome. Impacted is an unknown function of the file dist/service-worker.production-esm.js of the component Google OAuth Client Secret. Such manipulation leads to hard-coded credentials. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was informed beforehand about the issue. The support explains, that \"[a]t the moment, the [bug bounty] programme is on hold while we work through a large number of existing reports.\""
}
],
"metrics": [
{
"cvssV4_0": {
"baseScore": 6.9,
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P",
"version": "4.0"
}
},
{
"cvssV3_1": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.1"
}
},
{
"cvssV3_0": {
"baseScore": 7.3,
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R",
"version": "3.0"
}
},
{
"cvssV2_0": {
"baseScore": 7.5,
"vectorString": "AV:N/AC:L/Au:N/C:P/I:P/A:P/E:POC/RL:ND/RC:UR",
"version": "2.0"
}
}
],
"problemTypes": [
{
"descriptions": [
{
"cweId": "CWE-798",
"description": "Hard-coded Credentials",
"lang": "en",
"type": "CWE"
}
]
},
{
"descriptions": [
{
"cweId": "CWE-259",
"description": "Use of Hard-coded Password",
"lang": "en",
"type": "CWE"
}
]
}
],
"providerMetadata": {
"dateUpdated": "2026-08-31T16:15:09.377Z",
"orgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"shortName": "VulDB"
},
"references": [
{
"name": "VDB-397227 | Inbox Foundry ActiveInbox Extension Google OAuth Client Secret service-worker.production-esm.js hard-coded credentials",
"tags": [
"vdb-entry"
],
"url": "https://vuldb.com/vuln/397227"
},
{
"name": "VDB-397227 | CTI Indicators (IOB, IOC, TTP, IOA)",
"tags": [
"signature",
"permissions-required"
],
"url": "https://vuldb.com/vuln/397227/cti"
},
{
"name": "CVE-2026-82808 | CVE Analysis and Report",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/cve/CVE-2026-82808"
},
{
"name": "Submit #874121 | The Inbox Foundry Limited ActiveInbox: Organize Gmail tasks 7.10.24 Hard-coded Credentials",
"tags": [
"third-party-advisory"
],
"url": "https://vuldb.com/submit/874121"
},
{
"tags": [
"exploit"
],
"url": "https://github.com/xryj920/chrome_extensions/blob/main/The%20Inbox%20Foundry%20Limited%20ActiveInbox%207.10.24%20ships%20a%20hardcoded%20Google%20OAuth%20client%20secret%20in%20the%20Chrome%20extension%20bundle"
}
],
"timeline": [
{
"lang": "en",
"time": "2026-08-31T00:00:00.000Z",
"value": "Advisory disclosed"
},
{
"lang": "en",
"time": "2026-08-31T02:00:00.000Z",
"value": "VulDB entry created"
},
{
"lang": "en",
"time": "2026-08-31T06:53:39.000Z",
"value": "VulDB entry last update"
}
],
"title": "Inbox Foundry ActiveInbox Extension Google OAuth Client Secret service-worker.production-esm.js hard-coded credentials",
"x_generator": [
"VulDB PVTS v202608"
]
}
},
"cveMetadata": {
"assignerOrgId": "1af790b2-7ee1-4545-860a-a788eba489b5",
"assignerShortName": "VulDB",
"cveId": "CVE-2026-82808",
"datePublished": "2026-08-31T16:15:09.377Z",
"dateReserved": "2026-08-31T04:48:20.500Z",
"dateUpdated": "2026-08-31T19:02:39.743Z",
"state": "PUBLISHED"
},
"dataType": "CVE_RECORD",
"dataVersion": "5.2"
}
Mitigation
For outbound authentication: store passwords outside of the code in a strongly-protected, encrypted configuration file or database that is protected from access by all outsiders, including other local users on the same system. Properly protect the key (CWE-320). If you cannot use encryption to protect the file, then make sure that the permissions are as restrictive as possible.
Mitigation
For inbound authentication: Rather than hard-code a default username and password for first time logins, utilize a "first login" mode that requires the user to enter a unique strong password.
Mitigation
Perform access control checks and limit which entities can access the feature that requires the hard-coded password. For example, a feature might only be enabled through the system console instead of through a network connection.
Mitigation
- For inbound authentication: apply strong one-way hashes to your passwords and store those hashes in a configuration file or database with appropriate access control. That way, theft of the file/database still requires the attacker to try to crack the password. When receiving an incoming password during authentication, take the hash of the password and compare it to the hash that you have saved.
- Use randomly assigned salts for each separate hash that you generate. This increases the amount of computation that an attacker needs to conduct a brute-force attack, possibly limiting the effectiveness of the rainbow table method.
Mitigation
For front-end to back-end connections: Three solutions are possible, although none are complete.
No CAPEC attack patterns related to this CWE.