PT-2026-50648 · Worksnaps · Worksnaps

CVE-2025-10560

·

Published

2026-06-18

·

Updated

2026-06-21

CVSS v4.0

9.3

Critical

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Worksnaps versions prior to 1.6.20260201
Description The Worksnaps client application binaries contain hardcoded cloud credentials and secret material. These exposed credentials include AWS access keys and S3 bucket names, which authenticated as the AWS account root identity. This allows an attacker with access to the affected binaries to extract the credentials and gain complete access to production cloud resources, including S3 buckets containing sensitive data such as user desktop screenshots.
Recommendations Update to version 1.6.20260201 or later.

Fix

Using Hardcoded Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-10560

Affected Products

Worksnaps