CVE-2026-8878 PUBLISHED

CVE-2026-8878

Assigner: certcc
Reserved: 18.05.2026 Published: 03.06.2026 Updated: 04.06.2026

Version 3.0.7 of the Securly Chrome Extension exposes multiple publicly accessible endpoints that allow unauthenticated access to sensitive data. The exposed information consists of SHA-1 hashes that are inadequately obfuscated using a simple Caesar cipher, which can be easily reversed to recover the original hash values and access the protected data.

Product Status

Vendor Securly
Product Securly Chrome Extension
Versions
  • affected from 0 to 3.0.7 (incl.)

References

Problem Types

  • CWE-922 Insecure Storage of Sensitive Information