{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/lansweeper/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":5.5,"id":"CVE-2026-39031"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["lsrunase (2.0)","lsencrypt (2.0)"],"_cs_severities":["low"],"_cs_tags":["cve-2026-39031","credential-theft","cryptography"],"_cs_type":"advisory","_cs_vendors":["Lansweeper"],"content_html":"\u003cp\u003eCVE-2026-39031 identifies a severe cryptographic design flaw in Lansweeper's lsrunase 2.0 and lsencrypt 2.0 tools. The software utilizes a reversible RC4-based encryption scheme to store credentials, relying on a static 142-byte suffix hardcoded within the binary and an 8-character plaintext prefix stored alongside the ciphertext.\u003c/p\u003e\n\u003cp\u003eBecause the encryption process does not utilize per-installation or per-user secrets and uses a predictable key derivation process (SHA-1 over the hardcoded suffix and the plaintext prefix), any attacker with local access to the encrypted password strings can trivially recover the plaintext credentials offline. This vulnerability allows for unauthorized password recovery without any brute-force requirements, directly exposing administrative credentials, facilitating lateral movement, and enabling the retroactive decryption of previously captured or backed-up password strings.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows local attackers to decrypt stored credentials managed by Lansweeper tools. This compromise can lead to full privilege escalation if the recovered credentials have administrative rights, and enables lateral movement across the network where those accounts are authorized. Given the prevalence of these tools in administrative environments, this vulnerability significantly increases the risk of credential harvesting and identity-based attacks.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eInventory all systems running Lansweeper lsrunase 2.0 or lsencrypt 2.0.\u003c/li\u003e\n\u003cli\u003eImplement strict access controls to the configuration files or registry keys where these encrypted strings are stored to prevent unauthorized access by local users.\u003c/li\u003e\n\u003cli\u003eRotate all credentials that were previously stored using these versions of lsrunase or lsencrypt.\u003c/li\u003e\n\u003cli\u003eMigrate away from these legacy tools to modern, secure credential management solutions that support strong, non-reversible encryption standards.\u003c/li\u003e\n\u003cli\u003eMonitor file access events for the configuration locations of these specific tools to identify potential harvesting attempts.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-06T09:49:04Z","date_published":"2026-09-06T09:49:04Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-39031-lansweeper/","summary":"CVE-2026-39031 is a critical credential security flaw in Lansweeper lsrunase 2.0 and lsencrypt 2.0 that allows attackers to perform offline decryption of stored passwords.","title":"Lansweeper lsrunase and lsencrypt Password Recovery Vulnerability","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-39031-lansweeper/"}],"language":"en","title":"CraftedSignal Threat Feed - Lansweeper","version":"https://jsonfeed.org/version/1.1"}