Skip to content
Threat Feed
medium threat exploited

Default Credential Vulnerability in lenve vhr

The lenve vhr 1.0-SNAPSHOT application contains a vulnerability in vhr.sql involving the use of default credentials, enabling remote exploitation via publicly available exploit code.

CVE search metadata

CVE search record: CVE-2026-90498. Severity: high. CVSS: 7.3. KEV: no. Product: vhr (1.0-SNAPSHOT). Brief: Default Credential Vulnerability in lenve vhr. Brief link: https://feed.craftedsignal.io/briefs/2026-09-cve-2026-90498-vhr-default-creds/

A security vulnerability has been identified in the lenve vhr 1.0-SNAPSHOT application, specifically within the vhr.sql file. The vulnerability stems from the use of default credentials, which can be leveraged by remote attackers to gain unauthorized access to the application. This issue is categorized with a CVSS v3.1 base score of 7.3. Exploitation code for this vulnerability is currently publicly available, increasing the risk of active exploitation. The vendor has not responded to disclosure attempts, and no official patch is currently available for this version.

Impact

Successful exploitation of this vulnerability allows unauthorized remote users to bypass authentication mechanisms by leveraging default credentials. This could lead to full compromise of the vhr application, unauthorized data access, or administrative control over the service. Given that exploit code is publicly available, organizations currently running the 1.0-SNAPSHOT version of vhr are at elevated risk of credential-based attacks.

Recommendation

  • Identify all instances of lenve vhr 1.0-SNAPSHOT in your environment.
  • Immediately change default credentials for all administrative and database accounts associated with vhr.
  • Restrict network access to the vhr application to authorized segments only.
  • Monitor for unauthorized authentication attempts or credential-based login anomalies directed at the vhr application.

Immediate actions

Change all default credentials for vhr application

IT Operations 24h

Mitigations

Isolate vhr application from the internet

immediate IT Operations

CVE-2026-90498