CVE-2026-17038
DrEryk Gabinet vor Version 11.5.0 verwendet hartecodierte API-Anmeldeinformationen in seinem Ticket-Berichtskomponente (CVE-2026-17038)
medium
Beschreibung
DrEryk Gabinet vor Version 11.5.0 verwendet hartecodierte API-Anmeldeinformationen in seinem Ticket-Berichtskomponente. Diese Anmeldeinformationen können zur Authentifizierung direkt an die Ticket-System-API verwendet werden. Dies ermöglicht einem Angreifer, privilegierte Operationen über das hinaus auszuführen, was von der Anwendung angeboten wird, einschließlich des Lesens und Modifizierens von Tickets.
Metriken
Severity
medium
64.50
kein öffentlicher PoC bekannt
6.9
EPSS-Score
—
Veröffentlicht
2026-09-10 12:02 UTC
CWE-798
Weakness-Klassen (CWE)
CWE-798Base
Use of Hard-coded Credentials
The product contains hard-coded credentials, such as a password or cryptographic key.
cwe.mitre.org →
Re-Analyse & Statuswechsel
Chronologie der NVD-Audit-Events für diese CVE — Reanalyses, CVSS-Updates, CPE-Diffs.
- New CVE Received2026-09-10 13:17 UTC· cvd@cert.pl
- Description: DrEryk Gabinet before 11.5.0 uses hard-coded API credentials in its ticket reporting component. These credentials can be used to authenticate directly to the ticket system API. This allows an attacker to perform privileged operations beyond what is offered by the application, including reading and modifying tickets.
- CVSS V4.0: AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
- CWE: CWE-798
- Affected: New affected value received. <a href="https://github.com/CVEProject/cvelistV5/blob/main/cves/2026/17xxx/CVE-2026-17038.json">CVE-2026-17038</a>
- CVE Modified2026-09-10 13:17 UTC· 134c704f-9b21-4f2e-91b3-4a467353bcc0
- SSVC: {"id":"CVE-2026-17038","role":"CISA Coordinator","options":[{"exploitation":"none"},{"automatable":"yes"},{"technical…
Quellen & Referenzen
IDCVE-2026-17038