Hard-Coded API Credentials in DrEryk Gabinet by DrEryk
CVE-2026-17038
6.9MEDIUM
What is CVE-2026-17038?
The DrEryk Gabinet application prior to version 11.5.0 contains serious security flaws due to hard-coded API credentials in its ticket reporting module. These credentials enable attackers to authenticate directly to the ticket system API, permitting them to execute privileged actions that exceed the intended capabilities of the application. Potential risks include unauthorized access to sensitive information, modification of existing tickets, and the ability to create or delete records within the system.
Affected Version(s)
drEryk Gabinet 0 < 11.5.0
