🔐 CVE Alert

CVE-2026-17038

UNKNOWN 0.0

Use of Hard-coded Credentials in drEryk Gabinet

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

DrEryk Gabinet before 11.5.0 uses hard-coded API credentials in its ticket reporting component. These credentials can be used to authenticate directly to the ticket system API. This allows an attacker to perform privileged operations beyond what is offered by the application, including reading and modifying tickets.

CWE CWE-798
Vendor dreryk
Product dreryk gabinet
Published Sep 10, 2026
Last Updated Sep 10, 2026
Stay Ahead of the Next One

Get instant alerts for dreryk dreryk gabinet

Be the first to know when new unknown vulnerabilities affecting dreryk dreryk gabinet are published — delivered to Slack, Telegram or Discord.

Get Free Alerts → Free · No credit card · 60 sec setup

Affected Versions

drEryk / drEryk Gabinet
0 < 11.5.0

References

NVD ↗ CVE.org ↗ EPSS Data ↗
dreryk.pl: https://dreryk.pl/produkty/gabinet/ cert.pl: https://cert.pl/posts/2026/09/CVE-2026-17038

Credits

Wojciech Giełda