CVE-2026-92759

Summary

SecObserve versions before 1.59.1 contain an information disclosure vulnerability in the ApiConfigurationSerializer that fails to strip the basic_auth_password field from API configuration responses. View-only product members can retrieve the decrypted basic-auth password of configured scanner or integration service accounts through standard REST endpoints.

Affected Software

VendorProductVersion RangeStatus
SecObserveSecObserve1.17.0 < 1.59.1affected

Weaknesses

  • CWE-522: Insufficiently Protected Credentials

References