PT-2026-73192 · Acer · Planet9
CVSS v4.0
6.6
Medium
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:U |
Name of the Vulnerable Software and Affected Versions
Planet9 (affected versions not specified)
Description
The Planet9 desktop application contains a hardcoded read-only API key that allows unauthorized access to internal repositories. This flaw enables an attacker to extract embedded administrative keys and secrets, which could lead to administrative access to the repository infrastructure and the ability to modify software source code.
Recommendations
Update the application to the latest version released by Acer.
Fix
Using Hardcoded Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Planet9