Hard-Coded API Credentials in DrEryk Gabinet by DrEryk
CVE-2026-17038

6.9MEDIUM

Key Information:

Vendor

Dreryk

Vendor
CVE Published:
10 September 2026

What is CVE-2026-17038?

The DrEryk Gabinet application prior to version 11.5.0 contains serious security flaws due to hard-coded API credentials in its ticket reporting module. These credentials enable attackers to authenticate directly to the ticket system API, permitting them to execute privileged actions that exceed the intended capabilities of the application. Potential risks include unauthorized access to sensitive information, modification of existing tickets, and the ability to create or delete records within the system.

Affected Version(s)

drEryk Gabinet 0 < 11.5.0

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Wojciech Giełda
.