{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/lenve/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:lenve:vhr:1.0:snapshot:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.3,"id":"CVE-2026-90498"}],"_cs_exploited":true,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["vhr (1.0-SNAPSHOT)"],"_cs_severities":["medium"],"_cs_tags":["vulnerability","credential-exposure","cve"],"_cs_type":"threat","_cs_vendors":["lenve"],"content_html":"\u003cp\u003eA security vulnerability has been identified in the lenve vhr 1.0-SNAPSHOT application, specifically within the vhr.sql file. The vulnerability stems from the use of default credentials, which can be leveraged by remote attackers to gain unauthorized access to the application. This issue is categorized with a CVSS v3.1 base score of 7.3. Exploitation code for this vulnerability is currently publicly available, increasing the risk of active exploitation. The vendor has not responded to disclosure attempts, and no official patch is currently available for this version.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthorized remote users to bypass authentication mechanisms by leveraging default credentials. This could lead to full compromise of the vhr application, unauthorized data access, or administrative control over the service. Given that exploit code is publicly available, organizations currently running the 1.0-SNAPSHOT version of vhr are at elevated risk of credential-based attacks.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eIdentify all instances of lenve vhr 1.0-SNAPSHOT in your environment.\u003c/li\u003e\n\u003cli\u003eImmediately change default credentials for all administrative and database accounts associated with vhr.\u003c/li\u003e\n\u003cli\u003eRestrict network access to the vhr application to authorized segments only.\u003c/li\u003e\n\u003cli\u003eMonitor for unauthorized authentication attempts or credential-based login anomalies directed at the vhr application.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-13T07:24:28Z","date_published":"2026-09-13T07:24:28Z","id":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-90498-vhr-default-creds/","summary":"The lenve vhr 1.0-SNAPSHOT application contains a vulnerability in vhr.sql involving the use of default credentials, enabling remote exploitation via publicly available exploit code.","title":"Default Credential Vulnerability in lenve vhr","url":"https://feed.craftedsignal.io/briefs/2026-09-cve-2026-90498-vhr-default-creds/"}],"language":"en","title":"CraftedSignal Threat Feed - Lenve","version":"https://jsonfeed.org/version/1.1"}