Unauthorized QR Code Generation in Virtuagym Application
CVE-2026-12587
8.6HIGH
What is CVE-2026-12587?
The Virtuagym application is susceptible to unauthorized QR code generation stemming from hard-coded credentials. An attacker can exploit this flaw by utilizing a static 'badge_number' parameter as the HMAC private key, which can be accessed through the API endpoint '/club/id_club/member/id_member/resamania_qr_info'. Without code obfuscation, the application's cryptographic logic is vulnerable to reverse engineering, allowing attackers to generate valid QR codes perpetually, regardless of user actions such as password changes or logging out.
Affected Version(s)
Virtuagym 0 <= 21/08/2026
