๐Ÿ” CVE Alert

CVE-2026-90509

HIGH 7.3

dromara orion-visor ExposeApiAspect.java ExposeApiAspect.beforeExposeApi hard-coded credentials

CVSS Score
7.3
EPSS Score
0.0%
EPSS Percentile
0th

A weakness has been identified in dromara orion-visor up to 2.5.7. Affected by this issue is the function ExposeApiAspect.beforeExposeApi of the file ExposeApiAspect.java. Executing a manipulation can lead to hard-coded credentials. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet.

CWE CWE-798 CWE-259
Vendor dromara
Product orion-visor
Published Sep 13, 2026
Stay Ahead of the Next One

Get instant alerts for dromara orion-visor

Be the first to know when new high vulnerabilities affecting dromara orion-visor are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L/E:P/RL:X/RC:R
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

dromara / orion-visor
2.5.0 2.5.1 2.5.2 2.5.3 2.5.4 2.5.5 2.5.6 2.5.7

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/403097 vuldb.com: https://vuldb.com/vuln/403097/cti vuldb.com: https://vuldb.com/cve/CVE-2026-90509 vuldb.com: https://vuldb.com/submit/911864 github.com: https://github.com/dromara/orion-visor/issues/170 github.com: https://github.com/sumo166/CVE-apply/blob/main/dromara-orion-visor/ExposeApi%20Hardcoded%20Default%20Token%20Authentication%20Bypass%20(CWE-798)_en.md github.com: https://github.com/dromara/orion-visor/

Credits

๐Ÿ” summmm (VulDB User) VulDB CNA Team