Cleartext Password Storage Vulnerability in rust-iot-platform by IoT Ecology
CVE-2026-82453

8.7HIGH

Key Information:

Vendor
CVE Published:
29 August 2026

What is CVE-2026-82453?

The rust-iot-platform has a significant security issue where user passwords are stored in cleartext. This vulnerability arises from a flaw in the user model, leading to the potential exposure of plaintext credentials through API responses during user retrieval or listing actions. Attackers targeting this weakness can easily obtain sensitive login information, posing a severe risk to all user accounts. Immediate measures are recommended to mitigate the risks associated with this vulnerability.

Affected Version(s)

rust-iot-platform 0 <= 5df942ab6bc46a3bf83dbee8c7970554f92c972d

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Harsh Raj Singhania
.