Hard-Coded Credentials Vulnerability in VOCALOID6 by Yamaha
CVE-2026-76131

6.9MEDIUM

Key Information:

Status
Vendor
CVE Published:
21 August 2026

What is CVE-2026-76131?

A vulnerability has been identified in VOCALOID6 due to the use of hard-coded credentials, allowing potential attackers to impersonate legitimate users of the VOCALOID6 Editor. This flaw can enable unauthorized access to Yamaha's activation and content servers, posing a significant risk to the security of user accounts and the integrity of the service provided by Yamaha.

Affected Version(s)

VOCALOID6 0 <= 6.13.1

References

CVSS V4

Score:
6.9
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.