Default Credentials Vulnerability in lenve vhr by Unknown Vendor
CVE-2026-90498
Key Information:
Badges
What is CVE-2026-90498?
A security vulnerability has been identified in lenve vhr version 1.0-SNAPSHOT, specifically within the file vhr.sql. This issue allows an attacker to exploit the product using default credentials that haven't been changed. The potential for remote exploitation exists, and public exploits for this vulnerability have been made available. Despite early notifications sent to the vendor concerning this security risk, no response has been recorded. Users are advised to assess their systems for this vulnerability and take appropriate action to secure their installations.
Affected Version(s)
vhr 1.0-SNAPSHOT
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
