Default Credential Vulnerability in lenve vhr
The lenve vhr 1.0-SNAPSHOT application contains a vulnerability in vhr.sql involving the use of default credentials, enabling remote exploitation via publicly available exploit code.
CVE search metadata
CVE search record: CVE-2026-90498. Severity: high. CVSS: 7.3. KEV: no. Product: vhr (1.0-SNAPSHOT). Brief: Default Credential Vulnerability in lenve vhr. Brief link: https://feed.craftedsignal.io/briefs/2026-09-cve-2026-90498-vhr-default-creds/
A security vulnerability has been identified in the lenve vhr 1.0-SNAPSHOT application, specifically within the vhr.sql file. The vulnerability stems from the use of default credentials, which can be leveraged by remote attackers to gain unauthorized access to the application. This issue is categorized with a CVSS v3.1 base score of 7.3. Exploitation code for this vulnerability is currently publicly available, increasing the risk of active exploitation. The vendor has not responded to disclosure attempts, and no official patch is currently available for this version.
Impact
Successful exploitation of this vulnerability allows unauthorized remote users to bypass authentication mechanisms by leveraging default credentials. This could lead to full compromise of the vhr application, unauthorized data access, or administrative control over the service. Given that exploit code is publicly available, organizations currently running the 1.0-SNAPSHOT version of vhr are at elevated risk of credential-based attacks.
Recommendation
- Identify all instances of lenve vhr 1.0-SNAPSHOT in your environment.
- Immediately change default credentials for all administrative and database accounts associated with vhr.
- Restrict network access to the vhr application to authorized segments only.
- Monitor for unauthorized authentication attempts or credential-based login anomalies directed at the vhr application.
Immediate actions
Change all default credentials for vhr application
Mitigations
Isolate vhr application from the internet
CVE-2026-90498