Unauthorized QR Code Generation in Virtuagym Application
CVE-2026-12587

8.6HIGH

Key Information:

Vendor

Resamania

Status
Vendor
CVE Published:
26 August 2026

What is CVE-2026-12587?

The Virtuagym application is susceptible to unauthorized QR code generation stemming from hard-coded credentials. An attacker can exploit this flaw by utilizing a static 'badge_number' parameter as the HMAC private key, which can be accessed through the API endpoint '/club/id_club/member/id_member/resamania_qr_info'. Without code obfuscation, the application's cryptographic logic is vulnerable to reverse engineering, allowing attackers to generate valid QR codes perpetually, regardless of user actions such as password changes or logging out.

Affected Version(s)

Virtuagym 0 <= 21/08/2026

References

CVSS V4

Score:
8.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pau Hinojosa
.