PT-2026-106364 · Schmooze · Schmooze

CVE-2026-85153

·

Published

2026-10-06

·

Updated

2026-10-06

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Schmooze app (affected versions not specified)
Description The application contains hardcoded credentials and cryptographic keys within the client package. An unauthenticated remote attacker can extract these secrets by decompiling the application, potentially leading to unauthorized access to cloud and backend resources and the ability to forge client requests.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85153

Affected Products

Schmooze