PT-2026-90829 · Dromara+1 · Orion-Visor

·

CVE-2026-90510

·

Published

2026-09-13

·

Updated

2026-09-14

CVSS v3.1

8.3

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions dromara orion-visor versions prior to 2.5.8
Description A remote attack is possible due to the use of a hard-coded cryptographic key within the encryptKey() function of the HostKeyServiceImpl class. This issue allows for the potential compromise of encrypted data handled by the system.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability. As a temporary workaround, restrict access to the encryptKey() function to minimize the risk of exploitation.

Exploit

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-90510

Affected Products

Orion-Visor