CVE-2026-37012
A vulnerability in pentestgpt/core/langfuse.py in PentestGPT 1.0.0 allows remote attackers to disclose sensitive user telemetry data via har
CVSS
7.5
Alto
EPSS
0.4%
p30
KEV
—
Exploit Today
9
0-100
Publicado: 27 ago 2026 · Última mod.: 1 sept 2026 · CWE-798
0.2%EPSS · 30 días0.4%
2026-08-282026-09-17
A vulnerability in pentestgpt/core/langfuse.py in PentestGPT 1.0.0 allows remote attackers to disclose sensitive user telemetry data via hardcoded API credentials.
CVECVSSEPSSKEVRExplotTítuloVis.
CVE-2026-814407.3 ALT—
——0Dell OpenManage Server Administrator, versions prior to 11.1.0.3, contains a Use of Hard-coded Credentials vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Unauthorized access.1dCVE-2026-927879.8 CRÍ31.2%
——9Feast through 0.66.0 fails to verify JWT token signatures before establishing user identity, allowing attackers to bypass all role-based access control by presenting an unverified token with a hardcoded claim value. Attackers can obtain trusted internal identity and gain unchecked read and write access to all entities, feature views, data sources, and permission policies on the server.2dCVE-2026-689508.8 ALT13.2%
——4The affected products use hard-coded credentials, which could allow an attacker to run the ftpd service as root, providing remote root file access where FTP is reachable.2dCVE-2026-668909.6 CRÍ9.7%
——3The affected products use hard-coded credentials, which could allow remote access to files with root privileges where FTP is reachable.2dCVE-2026-371529.8 CRÍ40.2%
——12TOTOLINK X5000R V9.1.0cu.2415_B20250515 was discovered to contain a hardcoded password for root access.2dCVE-2026-161418.1 ALT32.9%
——10OpenBMC's IPMI implementation, phosphor-net-ipmid, contains a logic flaw in which an unauthenticated client can force the RAKP Message 1 handler to return before it overwrites the authentication object's constructor defaults. The IPMI service then accepts a RAKP Message 3 whose HMAC is computed with the constant 20-byte 'userKey' initialized from the string '0penBmc' and an often-predictable 'bmcRandomNum'. Several downstream vendors implement phosphor-net-ipmid as their IPMI stack, such as NVIDIA and H3C.3d