Skip to content
Threat Feed

Tag

Hardcoded-Credentials

17 briefs RSS
critical advisory

9router Critical Vulnerability Chain Allows Remote Code Execution via Default Password and Plugin Exploitation

A critical vulnerability chain, CVE-2026-63732, in 9router version 0.4.59 allows a remote, unauthenticated attacker to achieve arbitrary code execution on the host operating system by leveraging a hardcoded default password for initial access, bypassing a local-only network restriction via Host header spoofing, and exploiting unvalidated arguments during MCP plugin registration to execute malicious code when a plugin's SSE endpoint is triggered.

9router 0.4.59 vulnerability remote-code-execution hardcoded-credentials webserver nodejs
2r 3t 1c 1i
critical advisory

Pheditor Hardcoded Admin Password Leads to Remote Code Execution (CVE-2026-55579)

Pheditor contains a critical vulnerability (CVE-2026-55579) where a hardcoded default password 'admin' with no forced change mechanism upon first login allows an unauthenticated attacker to gain full administrative access, enabling arbitrary file read/write and remote code execution through the application's terminal feature, leading to complete server compromise.

Pheditor +1 hardcoded-credentials rce web-application cve web-vulnerability command-injection php
1r 5t
critical advisory

Flowise Authentication Bypass via Hardcoded JWT Secrets (CVE-2026-56271)

Flowise versions 3.0.13 and earlier are vulnerable due to hardcoded default JWT secrets ('auth_token', 'refresh_token') and default audience/issuer values ('AUDIENCE', 'ISSUER'), allowing an attacker to forge valid JWTs and impersonate any user, including administrators, leading to an authentication bypass if environment variables are not explicitly set.

Flowise authentication-bypass jwt hardcoded-credentials web-application critical-vulnerability
2t 1c
critical advisory

Praisonai-platform Critical Authentication Bypass Due to Persistent Hardcoded JWT Secret

Praisonai-platform versions up to and including 0.1.4 are vulnerable to a critical authentication bypass stemming from a hardcoded JWT signing secret ('dev-secret-change-me') and a bypassed production guard, allowing unauthenticated attackers to forge JSON Web Tokens (JWTs) and impersonate any user, leading to complete access, privilege escalation to workspace owner, and potential resource destruction.

praisonai-platform authentication-bypass hardcoded-credentials jwt python web-application supply-chain
2r 4t 1i
critical advisory

PraisonAI Platform Vulnerable to JWT Forgery via Hardcoded Default Secret

The `praisonai-platform` package, versions 0.1.4 and below, is critically vulnerable to authentication bypass and privilege escalation due to a hardcoded default JWT signing secret (`dev-secret-change-me`) that is inadvertently enabled in default deployments, allowing an unauthenticated attacker to forge JWTs and impersonate any user.

praisonai-platform <= 0.1.4 authentication-bypass hardcoded-credentials jwt-forgery python supply-chain misconfiguration
2r 4t 3i
critical advisory

IBM Controller Hard-Coded Credentials Vulnerability (CVE-2026-5065)

IBM Controller versions 11.0.1, 11.1.0, 11.1.1, and 11.1.2 are vulnerable to hard-coded credentials (CVE-2026-5065), potentially allowing unauthorized access and control of the application.

Controller 11.0.1 +3 cve credential-access ibm hardcoded-credentials
2r 1t 1c
medium advisory

Open ISES Tickets Hardcoded Database Credentials Vulnerability

Open ISES Tickets before version 3.44.2 contains hardcoded MySQL database connection credentials in import_mdb.php, allowing unauthorized database access.

Tickets +1 cve-2026-48242 hardcoded-credentials database-access
2r 1c
high advisory

Open ISES Tickets Hardcoded MySQL Credentials Vulnerability (CVE-2026-48241)

Open ISES Tickets before version 3.44.2 contains hardcoded MySQL database credentials in loader.php, allowing an attacker with access to the source code or the file on a deployed installation to read the username, password, and database name and use them to connect to the database (CVE-2026-48241).

Tickets < 3.44.2 cve hardcoded credentials vulnerability database
2r 1t 1c
critical threat

Taiko AG1000-01A SMS Alert Gateway Hardcoded Credentials Vulnerability (CVE-2026-9139)

Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains a hard-coded credential vulnerability (CVE-2026-9139) in the embedded web configuration interface, allowing unauthenticated attackers with network access to recover administrative credentials directly from client-side JavaScript and gain full administrative access to the device.

AG1000-01A SMS Alert Gateway cve hardcoded-credentials network-device
2r 1t 1c
critical advisory

FreePBX Security-Reporting userman Unauthenticated Hard-Coded Credentials Vulnerability

FreePBX Security-Reporting userman versions 16.0.45 and prior (FreePBX 16) and 17.0.7 and prior (FreePBX 17) contain a critical vulnerability due to unauthenticated use of hard-coded credentials in the UCP interface, potentially allowing unauthorized access.

FreePBX Security-Reporting userman +1 freepbx hardcoded-credentials voip
2r
critical advisory

Vvveb Hardcoded Credentials Vulnerability in phpMyAdmin Container

Vvveb versions before 1.0.8.2 contain a hardcoded credentials vulnerability in the docker-compose-apache.yaml configuration, allowing unauthenticated attackers to access the phpMyAdmin container and gain unrestricted read and write access to the Vvveb database, leading to account takeover and data manipulation.

Vvveb +1 hardcoded-credentials phpmyadmin docker vulnerability
2r 1t 1c
high advisory

osuuu LightPicture Hardcoded Credentials Vulnerability (CVE-2026-6574)

CVE-2026-6574 allows remote attackers to manipulate the 'key' argument in the /public/install/lp.sql file via the API Upload Endpoint in osuuu LightPicture <= 1.2.2, leading to hardcoded credentials exposure.

cve-2026-6574 hardcoded-credentials web-application
2r 1t 1c
high advisory

Hardcoded Storage Credentials in Mobile App and Device Firmware (CVE-2025-10681)

CVE-2025-10681 describes a vulnerability where hardcoded storage credentials in a mobile app and device firmware, with inadequate permission limits and lack of expiration, could lead to unauthorized access to production storage containers.

cve-2025-10681 hardcoded-credentials ics-cert ot
2r 1t 1c
critical advisory

GoHarbor Harbor v2.15.0 and Below Vulnerable to Hardcoded Credentials

GoHarbor Harbor version 2.15.0 and below is vulnerable to the use of hard-coded credentials, allowing an attacker to use the default password and gain unauthorized access to the web UI.

vulnerability hardcoded-credentials goharbor
2r 1t
high advisory

HCL Aftermarket DPC Hardcoded Credentials Vulnerability (CVE-2025-55263)

HCL Aftermarket DPC is vulnerable to hardcoded sensitive data (CVE-2025-55263), potentially enabling attackers to access source code or retrieve hardcoded secrets from insecure repositories.

HCL Aftermarket DPC cve-2025-55263 hardcoded-credentials hcl
2r 2t
critical advisory

AstrBotDevs AstrBot Vulnerability Leads to Hardcoded Credentials (CVE-2026-7579)

CVE-2026-7579 describes a vulnerability in AstrBotDevs AstrBot up to version 4.16.0 where improper handling of the `auth.py` file in the dashboard component leads to hardcoded credentials being exposed, enabling remote exploitation.

AstrBot cve hardcoded-credentials web-application
2r 1t 1c
high advisory

PicoTronica e-Clinic Healthcare System ECHS 5.7 Hardcoded Credentials Vulnerability

PicoTronica e-Clinic Healthcare System ECHS 5.7 is vulnerable to remote hardcoded credential exploitation due to manipulation of the ADMIN_KEY argument in /cdemos/echs/priv/echs.js, potentially leading to unauthorized access.

e-Clinic Healthcare System ECHS 5.7 cve-2026-8032 hardcoded-credentials web-application
2r 1t 1c