<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Vhr (1.0-SNAPSHOT) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/vhr-1.0-snapshot/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Sun, 13 Sep 2026 07:24:28 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/vhr-1.0-snapshot/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Default Credential Vulnerability in lenve vhr</title><link>https://feed.craftedsignal.io/briefs/2026-09-cve-2026-90498-vhr-default-creds/</link><pubDate>Sun, 13 Sep 2026 07:24:28 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-cve-2026-90498-vhr-default-creds/</guid><description>The lenve vhr 1.0-SNAPSHOT application contains a vulnerability in vhr.sql involving the use of default credentials, enabling remote exploitation via publicly available exploit code.</description><content:encoded><![CDATA[<p>A security vulnerability has been identified in the lenve vhr 1.0-SNAPSHOT application, specifically within the vhr.sql file. The vulnerability stems from the use of default credentials, which can be leveraged by remote attackers to gain unauthorized access to the application. This issue is categorized with a CVSS v3.1 base score of 7.3. Exploitation code for this vulnerability is currently publicly available, increasing the risk of active exploitation. The vendor has not responded to disclosure attempts, and no official patch is currently available for this version.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation of this vulnerability allows unauthorized remote users to bypass authentication mechanisms by leveraging default credentials. This could lead to full compromise of the vhr application, unauthorized data access, or administrative control over the service. Given that exploit code is publicly available, organizations currently running the 1.0-SNAPSHOT version of vhr are at elevated risk of credential-based attacks.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Identify all instances of lenve vhr 1.0-SNAPSHOT in your environment.</li>
<li>Immediately change default credentials for all administrative and database accounts associated with vhr.</li>
<li>Restrict network access to the vhr application to authorized segments only.</li>
<li>Monitor for unauthorized authentication attempts or credential-based login anomalies directed at the vhr application.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">threat</category><category>vulnerability</category><category>credential-exposure</category><category>cve</category></item></channel></rss>