CVE-2026-44105

Summary

The credentials for the local user "user-app" may be exposed in log files, potentially enabling a low-privileged local attacker with access to the logs to authenticate via SSH as the limited user "user-app". Charging could be interrupted.

Affected Software

VendorProductVersion RangeStatus
Phoenix ContactCHARX SEC-31501.0.0 < 1.9.1affected
Phoenix ContactCHARX SEC-31001.0.0 < 1.9.1affected
Phoenix ContactCHARX SEC-30501.0.0 < 1.9.1affected
Phoenix ContactCHARX SEC-30001.0.0 < 1.9.1affected

Weaknesses

  • CWE-532: CWE-532 Insertion of Sensitive Information into Log File

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References