CVE-2026-82808
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Summary
A vulnerability was identified in Inbox Foundry ActiveInbox Extension up to 7.10.24 on Chrome. Impacted is an unknown function of the file dist/service-worker.production-esm.js of the component Google OAuth Client Secret. Such manipulation leads to hard-coded credentials. The attack can be executed remotely. The exploit is publicly available and might be used. The vendor was informed beforehand about the issue. The support explains, that "[a]t the moment, the [bug bounty] programme is on hold while we work through a large number of existing reports."
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Inbox Foundry | ActiveInbox Extension | 7.10.0 | affected |
| Inbox Foundry | ActiveInbox Extension | 7.10.1 | affected |
| Inbox Foundry | ActiveInbox Extension | 7.10.2 | affected |
| Inbox Foundry | ActiveInbox Extension | 7.10.3 | affected |
| Inbox Foundry | ActiveInbox Extension | 7.10.4 | affected |
| Inbox Foundry | ActiveInbox Extension | 7.10.5 | affected |
| Inbox Foundry | ActiveInbox Extension | 7.10.6 | affected |
| Inbox Foundry | ActiveInbox Extension | 7.10.7 | affected |
| Inbox Foundry | ActiveInbox Extension | 7.10.8 | affected |
| Inbox Foundry | ActiveInbox Extension | 7.10.9 | affected |
| Inbox Foundry | ActiveInbox Extension | 7.10.10 | affected |
| Inbox Foundry | ActiveInbox Extension | 7.10.11 | affected |
| Inbox Foundry | ActiveInbox Extension | 7.10.12 | affected |
| Inbox Foundry | ActiveInbox Extension | 7.10.13 | affected |
| Inbox Foundry | ActiveInbox Extension | 7.10.14 | affected |
| Inbox Foundry | ActiveInbox Extension | 7.10.15 | affected |
| Inbox Foundry | ActiveInbox Extension | 7.10.16 | affected |
| Inbox Foundry | ActiveInbox Extension | 7.10.17 | affected |
| Inbox Foundry | ActiveInbox Extension | 7.10.18 | affected |
| Inbox Foundry | ActiveInbox Extension | 7.10.19 | affected |
| Inbox Foundry | ActiveInbox Extension | 7.10.20 | affected |
| Inbox Foundry | ActiveInbox Extension | 7.10.21 | affected |
| Inbox Foundry | ActiveInbox Extension | 7.10.22 | affected |
| Inbox Foundry | ActiveInbox Extension | 7.10.23 | affected |
| Inbox Foundry | ActiveInbox Extension | 7.10.24 | affected |
Weaknesses
- CWE-798: Hard-coded Credentials
- CWE-259: Use of Hard-coded Password
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: poc
- Automatable: yes
- Technical Impact: partial
Additional References
References
- https://vuldb.com/vuln/397227
- https://vuldb.com/vuln/397227/cti
- https://vuldb.com/cve/CVE-2026-82808
- https://vuldb.com/submit/874121
- https://github.com/xryj920/chrome_extensions/blob/main/The%20Inbox%20Foundry%20Limited%20ActiveInbox%207.10.24%20ships%20a%20hardcoded%20Google%20OAuth%20client%20secret%20in%20the%20Chrome%20extension%20bundle
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.