Hardcoded Cryptographic Keys and Weak IV Generation in Linqi Application
CVE-2026-11347

8.5HIGH

Key Information:

Vendor

Linqi Gmbh

Status
Vendor
CVE Published:
5 June 2026

What is CVE-2026-11347?

The linqi application contains hardcoded cryptographic keys. Additionally, the application uses a weak algorithm with a limited ASCII charset to dynamically generate Initialization Vectors (IVs) for AES/CBC encryption, making known-plaintext attacks feasible. An attacker with local access can leverage these vulnerabilities to decrypt sensitive obfuscated strings, including ConnectionString values containing database credentials from appsettings.json.

Affected Version(s)

linqi 0 <= 1.4.8.5

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Ianis BERNARD from NATO Cyber Security Centre (NCSC)
.