CVE-2026-16581
Inclusion of sensitive information in source code in igloohome Smart Lock Mobile Application
CVSS Score
5.3
EPSS Score
0.0%
EPSS Percentile
0th
In igloohome Smart Lock Mobile App versions 3.2.3 and prior, an Inclusion of Sensitive Information in Source Code vulnerability could allow an unauthorized actor to access functions or backend services that were not sufficiently protected by authentication controls.
| CWE | CWE-540 |
| Vendor | igloohome |
| Product | smart lock mobile application |
| Published | Jul 28, 2026 |
Stay Ahead of the Next One
Get instant alerts for igloohome smart lock mobile application
Be the first to know when new medium vulnerabilities affecting igloohome smart lock mobile application are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
None
Availability
None
Affected Versions
igloohome / Smart Lock Mobile Application
Version 3.2.3
References
Credits
Vincent C. of CodeVispera reported this vulnerability to CISA.