Site-level API Key Vulnerability in Kalcaddle Kodbox Product
CVE-2026-4588
What is CVE-2026-4588?
A vulnerability exists in the Kalcaddle Kodbox version 1.64, specifically within the function shareSafeGroup located in the file /workspace/source-code/app/controller/explorer/shareOut.class.php. This vulnerability arises from a manipulation within the function, resulting in the use of a hard-coded cryptographic key which could potentially allow an attacker to exploit the API key handler remotely. Although the complexity of executing an attack is high, the exploit has been publicly disclosed and may pose a risk if left unaddressed. It is important to note that the vendor was alerted about this vulnerability but failed to respond.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
kodbox 1.64
