{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/orion-visor--2.5.7/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:dromara:orion-visor:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.3,"id":"CVE-2026-90510"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["orion-visor (\u003c= 2.5.7)"],"_cs_severities":["high"],"_cs_tags":["vulnerability","credential-exposure","webserver"],"_cs_type":"advisory","_cs_vendors":["Dromara"],"content_html":"\u003cp\u003eDromara orion-visor, an asset management platform, is vulnerable to a security flaw identified as CVE-2026-90510. The vulnerability stems from the use of a hard-coded cryptographic key within the HostKeyServiceImpl.encryptKey function, located in the file orion-visor-modules/orion-visor-module-asset/orion-visor-module-asset-service/src/main/java/org/dromara/visor/module/asset/service/impl/HostKeyServiceImpl.java.\u003c/p\u003e\n\u003cp\u003eBecause the key is hard-coded into the source code, encryption for host keys is predictable, undermining the confidentiality of stored credentials. Attackers can leverage this fixed key to decrypt sensitive host keys remotely. The vulnerability was disclosed publicly following a failure by the project maintainers to address an early issue report. As of the current disclosure, no patch is available. Defenders should note that this vulnerability exposes the underlying infrastructure managed by orion-visor to significant risk, as the compromise of host keys often leads to unauthorized access to downstream systems.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows remote attackers to compromise host key encryption, leading to the exposure of credentials used for remote server access. This could facilitate lateral movement, further unauthorized access to managed assets, and potential full system compromise for all hosts integrated with the affected orion-visor instance.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritize the identification and isolation of internet-facing orion-visor instances. Since no vendor patch exists, consider restricting access to the web interface to authorized management subnets only until a fix is released. Audit existing host key configurations for signs of unauthorized access or modification.\u003c/p\u003e\n","date_modified":"2026-09-13T13:25:15Z","date_published":"2026-09-13T11:25:14Z","id":"https://feed.craftedsignal.io/briefs/2026-09-orion-visor-hardcoded-key/","summary":"Orion-visor versions 2.5.7 and earlier contain a hard-coded cryptographic key within the HostKeyServiceImpl.encryptKey function, enabling potential remote compromise of encrypted host keys.","title":"Hard-coded Cryptographic Key Vulnerability in Orion-visor","url":"https://feed.craftedsignal.io/briefs/2026-09-orion-visor-hardcoded-key/"}],"language":"en","title":"CraftedSignal Threat Feed - Orion-Visor (\u003c= 2.5.7)","version":"https://jsonfeed.org/version/1.1"}