PT-2026-94041 · Unknown · Secobserve
CVSS v4.0
7.1
High
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
SecObserve versions prior to 1.59.1
Description
An information disclosure issue exists in the
ApiConfigurationSerializer which fails to remove the basic auth password field from API configuration responses. This allows users with view-only permissions to retrieve the decrypted basic-auth passwords of configured integration service accounts or scanners via standard REST endpoints.Recommendations
Update SecObserve to version 1.59.1 or later.
Exploit
Fix
Insufficiently Protected Credentials
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Secobserve