CVE-2026-2103
Last modified
CVE-2026-2103 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Infor SyteLine ERP uses hard-coded static cryptographic keys to encrypt stored credentials, including user passwords, database connection strings, and API keys. The encryption keys are identical across all installations. EPSS estimates a 0.10% chance of exploitation in the next 30 days.
Description
Infor SyteLine ERP uses hard-coded static cryptographic keys to encrypt stored credentials, including user passwords, database connection strings, and API keys. The encryption keys are identical across all installations. An attacker with access to the application binary and database can decrypt all stored credentials.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Infor | Syteline Erp | 10.0.8803.16889 |
References
- https://blog.blacklanternsecurity.com/p/cve-2026-2103-infor-syteline-erpExploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2026-2103?
How severe is CVE-2026-2103?
How do I fix CVE-2026-2103?
Are you affected by CVE-2026-2103?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
