PT-2026-94041 · Unknown · Secobserve

·

CVE-2026-92759

·

Published

2026-09-16

·

Updated

2026-09-16

CVSS v4.0

7.1

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions SecObserve versions prior to 1.59.1
Description An information disclosure issue exists in the ApiConfigurationSerializer which fails to remove the basic auth password field from API configuration responses. This allows users with view-only permissions to retrieve the decrypted basic-auth passwords of configured integration service accounts or scanners via standard REST endpoints.
Recommendations Update SecObserve to version 1.59.1 or later.

Exploit

Fix

Insufficiently Protected Credentials

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-92759
GHSA-R968-78VW-JJ9M

Affected Products

Secobserve