CVE-2026-1958
Last modified
CVE-2026-1958 is a high-severity vulnerability rated 8.7/10 on the CVSS scale. Use of hard-coded credentials in Klinika XP and KlinikaXP Insertino allowed an unauthorized attacker access to several internal services. Critically, this included access to the FTP server that hosted the application's update packages. EPSS estimates a 0.27% chance of exploitation in the next 30 days.
Description
Use of hard-coded credentials in Klinika XP and KlinikaXP Insertino allowed an unauthorized attacker access to several internal services. Critically, this included access to the FTP server that hosted the application's update packages. The attacker with these credentials could upload a malicious update file, which then may have been distributed and installed on client machines as a legitimate update. This issue affects KlinikaXP: before 5.39.01.01. and KlinikaXP Insertino before 3.1.0.1 Beside removing the hardcoded credentials from the code, previously exposed credentials were also rotated preventing further attack attempts.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-1958?
How severe is CVE-2026-1958?
How do I fix CVE-2026-1958?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-19557Use after free in TabStrip in Google Chrome on Mac prior to …8.3
- CVE-2026-19558Use after free in Extensions in Google Chrome prior to 151.0…7.5
- CVE-2026-19559Use after free in HTML in Google Chrome prior to 151.0.7922.…
- CVE-2026-19560Use after free in Blink in Google Chrome prior to 151.0.7922…8.8
- CVE-2026-19566Net::CIDR::Set versions before 0.23 for Perl allow memory ex…
- CVE-2026-19579Snipe-IT before 8.6.0 contains an authorization bypass (inse…5.4
- CVE-2026-19587Uncontrolled Resource Consumption vulnerability in Samsung O…6.5
- CVE-2026-19588Integer Overflow to Buffer Overflow vulnerability in Samsung…6.5
- CVE-2026-1959Stored Cross-Site Scripting (XSS) vulnerability in Loggro Py…5.1
- CVE-2026-19594Insufficient input sanitization in Snowflake Python API (`sn…8.1
- CVE-2026-1960Stored Cross-Site Scripting (XSS) vulnerability in Loggro Py…5.1
- CVE-2026-1961A flaw was found in Foreman. A remote attacker could exploit…8
Are you affected by CVE-2026-1958?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
