DrEryk Gabinet before 11.5.0 uses hard-coded API credentials in its ticket reporting component. These credentials can be used to authenticate directly to the ticket system API. This allows an attacker to perform privileged operations beyond what is offered by the application, including reading and modifying tickets.
CVSS
No CVSS.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-10 13:17
Updated : 2026-09-10 19:58
NVD link : CVE-2026-17038
Mitre link : CVE-2026-17038
CVE.ORG link : CVE-2026-17038
JSON object : View
Products Affected
No product.
CWE
CWE-798
Use of Hard-coded Credentials
