๐Ÿ” CVE Alert

CVE-2026-11347

UNKNOWN 0.0

Hardcoded Cryptographic Keys and Weak IV Generation in linqi

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
1th

The linqi application contains hardcoded cryptographic keys. Additionally, the application uses a weak algorithm with a limited ASCII charset to dynamically generate Initialization Vectors (IVs) for AES/CBC encryption, making known-plaintext attacks feasible. An attacker with local access can leverage these vulnerabilities to decrypt sensitive obfuscated strings, including ConnectionString values containing database credentials from appsettings.json.

CWE CWE-321 CWE-338
Vendor linqi gmbh
Product linqi
Published Jun 5, 2026
Last Updated Jun 5, 2026
Stay Ahead of the Next One

Get instant alerts for linqi gmbh linqi

Be the first to know when new unknown vulnerabilities affecting linqi gmbh linqi are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

linqi GmbH / linqi
0 โ‰ค 1.4.8.5

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
linqi.help: https://linqi.help/en/reference/security/security-advisories/#security-advisory-hardcoded-cryptographic-keys-and-weak-iv-generation-in-linqi

Credits

Ianis BERNARD from NATO Cyber Security Centre (NCSC)