PT-2026-50648 · Worksnaps · Worksnaps
CVE-2025-10560
·
Published
2026-06-18
·
Updated
2026-06-21
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:H/SI:H/SA:H |
Name of the Vulnerable Software and Affected Versions
Worksnaps versions prior to 1.6.20260201
Description
The Worksnaps client application binaries contain hardcoded cloud credentials and secret material. These exposed credentials include AWS access keys and S3 bucket names, which authenticated as the AWS account root identity. This allows an attacker with access to the affected binaries to extract the credentials and gain complete access to production cloud resources, including S3 buckets containing sensitive data such as user desktop screenshots.
Recommendations
Update to version 1.6.20260201 or later.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Worksnaps