๐Ÿ” CVE Alert

CVE-2026-92759

MEDIUM 6.5

SecObserve before 1.59.1 Information Disclosure via API Configuration

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

SecObserve versions before 1.59.1 contain an information disclosure vulnerability in the ApiConfigurationSerializer that fails to strip the basic_auth_password field from API configuration responses. View-only product members can retrieve the decrypted basic-auth password of configured scanner or integration service accounts through standard REST endpoints.

CWE CWE-522
Vendor secobserve
Product secobserve
Published Sep 16, 2026
Stay Ahead of the Next One

Get instant alerts for secobserve secobserve

Be the first to know when new medium vulnerabilities affecting secobserve secobserve are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

SecObserve / SecObserve
1.17.0 < 1.59.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/SecObserve/SecObserve/issues/4799 github.com: https://github.com/SecObserve/SecObserve github.com: https://github.com/SecObserve/SecObserve/security/advisories/GHSA-r968-78vw-jj9m github.com: https://github.com/SecObserve/SecObserve/blob/v1.54.0/backend/application/import_observations/api/serializers.py#L103-L119 github.com: https://github.com/SecObserve/SecObserve/releases/tag/v1.59.1 vulncheck.com: https://www.vulncheck.com/advisories/secobserve-before-1.59.1-information-disclosure-via-api-configuration

Credits

George Chen