Local User Credential Exposure in Log Files for User-App - Vendor Insights
CVE-2026-44105

5.8MEDIUM

Key Information:

Vendor
CVE Published:
30 July 2026

What is CVE-2026-44105?

The local user credentials for 'user-app' may inadvertently be recorded in log files, which can be accessed by low-privileged local attackers. This exposure allows these attackers to potentially authenticate via SSH as the 'user-app' user, leading to unauthorized access and possible service disruption. Protecting logging mechanisms is essential for maintaining secure operations and preventing malicious exploitation.

Affected Version(s)

CHARX SEC-3000 1.0.0 < 1.9.1

CHARX SEC-3050 1.0.0 < 1.9.1

CHARX SEC-3100 1.0.0 < 1.9.1

References

CVSS V4

Score:
5.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

ZDI
.