Use of Hard-coded Cryptographic Key in Hitachi Coding Software Suite
CVE-2026-82827

9.3CRITICAL

What is CVE-2026-82827?

The Hitachi Coding Software Suite is affected by a vulnerability related to the hard-coded cryptographic key used for signing JSON Web Tokens (JWT). This hardcoding allows attackers to generate unauthorized Bearer tokens, potentially exploiting administrative functions within the system. The impact of this vulnerability enables malicious entities to bypass authentication mechanisms, resulting in unauthorized access to sensitive data and controls. Users are advised to review their security practices and update to the latest software version to mitigate risks associated with this issue.

Affected Version(s)

Hitachi Coding Software Suite 0 <= 3.3.0

References

CVSS V4

Score:
9.3
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Michael Heinzl
.