CVE-2026-17038 PUBLISHED

Use of Hard-coded Credentials in drEryk Gabinet

Assigner: CERT-PL
Reserved: 24.07.2026 Published: 10.09.2026 Updated: 10.09.2026

DrEryk Gabinet before 11.5.0 uses hard-coded API credentials in its ticket reporting component. These credentials can be used to authenticate directly to the ticket system API. This allows an attacker to perform privileged operations beyond what is offered by the application, including reading and modifying tickets.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.9

Product Status

Vendor drEryk
Product drEryk Gabinet
Versions Default: unaffected
  • affected from 0 to 11.5.0 (excl.)

Credits

  • Wojciech Giełda finder

References

Problem Types

  • CWE-798 Use of Hard-coded Credentials CWE